RegDuke

Description

(ESET) A recovery first stage, which uses Dropbox as its C&C server. The main payload is encrypted on disk and the encryption key is stored in the Windows registry. It also relies on steganography as above.

Names

Name
RegDuke

Category

Malware

Type

  • Backdoor

Information

Mitre Attack

Other Information

Uuid

760f8de4-7a50-42ff-bd9e-fba58f5f5204

Last Card Change

2022-12-30