miniduke_indicators_public
ID: 7e571ed5-a45d-42ac-9e38-e96eefc6fd0f
STIX ID: report--7e571ed5-a45d-42ac-9e38-e96eefc6fd0f
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2013-02-27
Last Modified Date: 2013-02-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive summary
This CrySyS/Kaspersky technical report documents the Miniduke APT: multi-stage polymorphic malware with stage-2/3 payloads delivered via malicious documents, encrypted GIF-wrapped executables, and C2 discovery via Google/Twitter queries; the report enumerates numerous MD5/SHA1 IOCs, C2 servers (e.g., news.grouptumbler.com / 200.63.46.23), network request formats (Base64-like GET parameter decoding, geoip/twitter/google lookups), persistence artifacts (startup .lnk and .tmp/.cat/.db DLL exports), and detection signatures and heuristics for incident response.
