S0511Windows

S0511RegDuke

Platforms
1
ATT&CK
14.1
References
2

Description

[RegDuke](https://attack.mitre.org/software/S0511) is a first stage implant written in .NET and used by [APT29](https://attack.mitre.org/groups/G0016) since at least 2017. [RegDuke](https://attack.mitre.org/software/S0511) has been used to control a compromised machine when control of other implants on the machine was lost.(Citation: ESET Dukes October 2019)

Platforms· 1

Windows

References

  1. https://attack.mitre.org/software/S0511
  2. https://www.welivesecurity.com/wp-content/uploads/2019/10/ESET_Operation_Ghost_Dukes.pdf

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
MiniDuke
Software
FatDuke
Software
LiteDuke
Software
GeminiDuke
Software
SeaDuke
Software
OnionDuke
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.