logo

DAGGER_PANDA__2015__duqu2_crysys.pdf

ID: 58441b43-ea18-4d2f-93b3-777a0c8c85a5

STIX ID: report--58441b43-ea18-4d2f-93b3-777a0c8c85a5

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2015-06-10

Last Modified Date: 2015-06-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This CrySyS Lab technical report analyzes Duqu 2.0 samples received in 2015 and compares them to the original Duqu, demonstrating numerous code and behavior similarities (string decryption, AES/CTS-like config encryption, logging structures, import hashing, and C2 mechanisms), providing IOCs (sample hashes, GIF payload, YARA rules) and concluding the threat is a sophisticated APT-class cyber-espionage actor likely reusing and evolving prior Duqu toolsets.