DarkUniverse – the mysterious APT framework #27
ID: 6e447ddf-fdde-47df-9723-e076fbdc70ff
STIX ID: report--6e447ddf-fdde-47df-9723-e076fbdc70ff
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2019-11-20
Last Modified Date: 2019-11-20
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** This Kaspersky GReAT report details DarkUniverse, a sophisticated APT cyber-espionage framework active from 2009–2017 that used targeted spear-phishing with malicious Office documents to drop a multi-module malware suite (keylogger, POP3 credential stealer, flexible C2 via cloud storage, and a powerful command module) against around 20 victims across multiple countries; the report describes technical implementation, persistence, custom encryption, supported C2 commands, victimology and MD5 IOCs, and attributes the activity with medium confidence to the ItaDuke set of operations.
