Duqu is a highly sophisticated cyberespionage malware platform and threat cluster closely linked by researchers to Stuxnet through shared developmental lineage, code relationships, and platform design. It is best known for the original Duqu malware disclosed in 2011 and the later Duqu 2.0 platform uncovered in 2015. Duqu 2.0 is widely regarded as one of the most advanced in-memory espionage frameworks publicly documented, featuring a modular architecture with more than 100 observed plugin variants and support for multiple command-and-control transports including HTTP, HTTPS, SMB pipes, and custom TCP. Researchers have also described an intermediate evolutionary stage referred to as Duqu 1.5. Duqu operations have targeted high-value organizations and event-linked environments associated with sensitive diplomatic activity, including venues connected to the P5+1 nuclear negotiations with Iran. Victims have also been identified in Western countries, the Middle East, and Asia, and reporting has noted compromises tied to a commemorative event related to Auschwitz-Birkenau. The actor has additionally been associated with intrusions into security vendors and with utilitarian targeting of organizations that could enhance operational reach, including industrial or ICS-relevant entities. Operationally, Duqu has demonstrated strong capabilities in stealth, privilege escalation, lateral movement, and defense evasion. The original Duqu used msiexec to execute malicious Windows Installer packages. Duqu 2.0 also used MSI-based loaders for deployment and remote execution, including execution through services or Task Scheduler, with encrypted payloads decrypted via installer properties. The platform emphasized memory residency, modular plugin loading, and kernel-level operations. Public reporting states that Duqu 2.0 exploited CVE-2015-2360 in the Windows kernel to gain elevated privileges and load unsigned kernel-mode components, and its operators also used behavior consistent with exploitation of CVE-2014-6324 for domain privilege escalation as well as pass-the-hash for lateral movement. Duqu 2.0 supported process injection and migration behaviors, kernel-driver-assisted evasion, and covert communications techniques such as hiding command-and-control traffic inside image files and varying HTTP user-agent strings. Reporting also describes a malicious NDIS filter driver used to redirect traffic for covert tunneling inside victim networks. Researchers have noted deliberate false-flag artifacts in Duqu 2.0, including strings apparently intended to mislead attribution. Despite longstanding speculation about state sponsorship, public reporting in the supplied material does not provide definitive attribution to a specific country. Known related names and variants include Duqu, Duqu 1.5, and Duqu 2.0.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example adversary that abuses msiexec to execute malicious MSI packages.
Mentioned only as an example of a threat group covered by TeDi signatures.
Connected to Stuxnet development through the Tilde-D platform; the article also discusses Duqu 1.5 as an intermediate evolution between Duqu 1.0 and Duqu 2.0 discovered in a diplomatic venue intrusion.
A Stuxnet-linked espionage actor/platform family whose Tilde-D platform shared developmental links with Stuxnet; the article also describes an intermediate Duqu 1.5 stage between Duqu 1.0 and Duqu 2.0 discovered at a diplomatic venue.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.