DAGGER_PANDA__2015__duqu2_crysys.pdf
ID: 58441b43-ea18-4d2f-93b3-777a0c8c85a5
STIX ID: report--58441b43-ea18-4d2f-93b3-777a0c8c85a5
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2015-06-10
Last Modified Date: 2015-06-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This CrySyS Lab technical report analyzes Duqu 2.0 samples received in 2015 and compares them to the original Duqu, demonstrating numerous code and behavior similarities (string decryption, AES/CTS-like config encryption, logging structures, import hashing, and C2 mechanisms), providing IOCs (sample hashes, GIF payload, YARA rules) and concluding the threat is a sophisticated APT-class cyber-espionage actor likely reusing and evolving prior Duqu toolsets.
