duboki is a cybercrime operator associated with a pay-per-install botnet and loader-as-a-service operation active since at least early 2026. The operation used a trojanized copy of BCUninstaller as an initial infection vehicle and scaled to more than 16,000 infected systems across over 60 countries. Activity attributed to duboki shows a mid-tier criminal service model in which access to compromised hosts was sold to downstream customers, including for credential theft and cryptocurrency mining. The intrusion chain relied on social-engineering delivery, staged script execution, and a multi-stage command-and-control architecture. Malware delivery used a trojanized application component to execute malicious code, invoke PowerShell-based download cradles, and retrieve follow-on payloads. The operation employed a deterministic domain generation algorithm for command-and-control rotation, scheduled-task persistence running with elevated privileges, Microsoft Defender exclusion tampering, antivirus enumeration, AMSI bypass, and a custom Session 0 bypass utility that duplicated tokens from active user sessions and launched payloads into interactive contexts. Observed payloading included a credential stealer targeting browser, email, file-transfer, gaming, and Outlook data, as well as XMRig-based Monero mining. The service exhibited characteristics of the Russian-speaking cybercrime ecosystem. Attribution in available reporting links the operation to the handle "duboki" based on a PDB path, and customer activity overlapped with ACR Stealer-related criminal usage. The actor's tradecraft demonstrates capability in initial access, persistence, defense evasion, post-exploitation, credential theft, and monetization through bot sales and crypto-mining rather than ransomware or extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
31 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.