Duqu 2.0 is a highly sophisticated cyberespionage threat actor and malware platform associated with advanced intrusions against high-value targets. It is widely regarded as a nation-state espionage operation and has been linked by multiple public researchers to activity aligned with the broader Duqu lineage. The actor is known for stealthy post-compromise tradecraft, advanced persistence and defense-evasion techniques, and the use of privileged Windows exploitation, including techniques involving the Win32k subsystem and internal command-and-control proxying through compromised servers. Duqu 2.0 has been cited alongside other elite intrusion sets in connection with exploitation trends involving Win32k user-mode callback vulnerabilities and related kernel-level techniques. Its operations are characterized by covert access, in-memory or low-footprint tooling, and careful operational security consistent with long-term intelligence collection rather than financially motivated crime. The name is also written as Duqu 2.0.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.