RegDuke
S0511 · Windows
RegDuke is a first stage implant written in .NET and used by APT29 since at least 2017. RegDuke has been used to control a compromised machine when control of other implants on the machine was lost.
ATT&CK S0511
1 actors documented
Sigma rules0
YARA rules0
Live IOCs0