ATT&CKSoftwarePolyglotDuke

PolyglotDuke

S0518

Malware.View on attack.mitre.org

About this malware

PolyglotDuke is a downloader that has been used by APT29 since at least 2013. PolyglotDuke has been used to drop MiniDuke.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1027
Obfuscated Files or Information

PolyglotDuke can custom encrypt strings.

T1027.003
Steganography

PolyglotDuke can use steganography to hide C2 information in images.

T1027.011
Fileless Storage

PolyglotDuke can store encrypted JSON configuration files in the Registry.

T1071.001
Web Protocols

PolyglotDuke has has used HTTP GET requests in C2 communications.

T1102.001
Dead Drop Resolver

PolyglotDuke can use Twitter, Reddit, Imgur and other websites to get a C2 URL.

T1105
Ingress Tool Transfer

PolyglotDuke can retrieve payloads from the C2 server.

T1106
Native API

PolyglotDuke can use LoadLibraryW and CreateProcess to load and execute code.

T1112
Modify Registry

PolyglotDuke can write encrypted JSON configuration files to the Registry.

T1140
Deobfuscate/Decode Files or Information

PolyglotDuke can use a custom algorithm to decrypt strings used by the malware.

T1218.011
Rundll32

PolyglotDuke can be executed using rundll32.exe.

Groups that use it1

Campaigns1

References1

  1. ESET Dukes October 2019 Open source
    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.