RegDuke

S0511

Malware.View on attack.mitre.org

About this malware

RegDuke is a first stage implant written in .NET and used by APT29 since at least 2017. RegDuke has been used to control a compromised machine when control of other implants on the machine was lost.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1027
Obfuscated Files or Information

RegDuke can use control-flow flattening or the commercially available .NET Reactor for obfuscation.

T1027.003
Steganography

RegDuke can hide data in images, including use of the Least Significant Bit (LSB).

T1027.011
Fileless Storage

RegDuke can store its encryption key in the Registry.

T1059.001
PowerShell

RegDuke can extract and execute PowerShell scripts from C2 communications.

T1102.002
Bidirectional Communication

RegDuke can use Dropbox as its C2 server.

T1105
Ingress Tool Transfer

RegDuke can download files from C2.

T1112
Modify Registry

RegDuke can create seemingly legitimate Registry key to store its encryption key.

T1140
Deobfuscate/Decode Files or Information

RegDuke can decrypt strings with a key either stored in the Registry or hardcoded in the code.

T1546.003
Windows Management Instrumentation Event Subscription

RegDuke can persist using a WMI consumer that is launched every time a process named WINWORD.EXE is started.

Groups that use it1

Campaigns1

References1

  1. ESET Dukes October 2019 Open source
    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.