logo

miniduke_indicators_public

ID: 7e571ed5-a45d-42ac-9e38-e96eefc6fd0f

STIX ID: report--7e571ed5-a45d-42ac-9e38-e96eefc6fd0f

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2013-02-27

Last Modified Date: 2013-02-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive summary This CrySyS/Kaspersky technical report documents the Miniduke APT: multi-stage polymorphic malware with stage-2/3 payloads delivered via malicious documents, encrypted GIF-wrapped executables, and C2 discovery via Google/Twitter queries; the report enumerates numerous MD5/SHA1 IOCs, C2 servers (e.g., news.grouptumbler.com / 200.63.46.23), network request formats (Base64-like GET parameter decoding, geoip/twitter/google lookups), persistence artifacts (startup .lnk and .tmp/.cat/.db DLL exports), and detection signatures and heuristics for incident response.