logo

DarkUniverse – the mysterious APT framework #27

ID: 6e447ddf-fdde-47df-9723-e076fbdc70ff

STIX ID: report--6e447ddf-fdde-47df-9723-e076fbdc70ff

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2019-11-20

Last Modified Date: 2019-11-20

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** This Kaspersky GReAT report details DarkUniverse, a sophisticated APT cyber-espionage framework active from 2009–2017 that used targeted spear-phishing with malicious Office documents to drop a multi-module malware suite (keylogger, POP3 credential stealer, flexible C2 via cloud storage, and a powerful command module) against around 20 victims across multiple countries; the report describes technical implementation, persistence, custom encryption, supported C2 commands, victimology and MD5 IOCs, and attributes the activity with medium confidence to the ItaDuke set of operations.