Skip to main content
Mallory
MalwareUsed by 1 actor

DUPERUNNER

DUPERUNNER is a previously undocumented Windows implant, described by Seqrite as a C++ second-stage payload, used in the spear-phishing campaign Operation DupeHike / DUPEHIKE tracked as UNG0902. The activity targeted Russian corporate employees, especially HR, payroll, internal administrative, finance, accounting, procurement, and legal functions, using bonus- and policy-themed lures delivered via spear-phishing. Observed infection chains used ZIP archives containing PDF-themed malicious LNK files; when executed, the LNK launched hidden PowerShell to download and run the DUPERUNNER payload, including from 46[.]149[.]71[.]230, saving it as s.exe in the victim Temp directory.

DUPERUNNER retrieves and opens a decoy PDF for user deception, including downloading a file disguised as fontawesome_tld.woff and saving it to the Temp directory with a timestamp-based filename before opening it. It then downloads an additional payload disguised as fontawesome.woff and injects shellcode into legitimate Windows processes such as explorer.exe, notepad.exe, and msedge.exe using VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread. The injected payload is an AdaptixC2 beacon/stager, and reporting states DUPERUNNER ultimately loads AdaptixC2 via process injection.

Associated reporting ties DUPERUNNER to Operation DupeHike / DUPEHIKE and threat cluster UNG0902. Seqrite noted infrastructure hosted under AS48282 (VDSINA-AS) and AS9123 (TIMEWEB-AS). AdaptixC2 traffic was observed using HTTP POST, including a /result endpoint, and Seqrite extracted configuration artifacts such as a Beacon-ID, User-Agent, and C2 URL/host. High-confidence observables directly mentioned in the reporting include 46[.]149[.]71[.]230, the ZIP name "Премия 2025.zip," the malicious shortcut "Документ_1_О_размере_годовой_премии.pdf.lnk," and the disguised payload names fontawesome_tld.woff and fontawesome.woff.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UNG0902

...use of malicious LNK file, leading to ... unknown implant, which we have dubbed as DUPERUNNER, which finally loads the AdaptixC2 Beacon...

via seqrite comseqrite.com
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

T1055Process InjectionEvidence1

Operation DUPEHIKE Hits Russian HR: Bonus Lure Delivers DUPERUNNER and Adaptix C2 via Process Injection

Stealth

1 technique
T1055Process InjectionEvidence1

Operation DUPEHIKE Hits Russian HR: Bonus Lure Delivers DUPERUNNER and Adaptix C2 via Process Injection

INDICATORS OF COMPROMISE

IOCs tracked for this family

12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
11 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app6 months ago
hash.sha256●●●●●●●●●●●●View more in app6 months ago
hash.sha256●●●●●●●●●●●●View more in app6 months ago
hash.sha256●●●●●●●●●●●●View more in app6 months ago
hash.sha256●●●●●●●●●●●●View more in app6 months ago
hash.sha256●●●●●●●●●●●●View more in app6 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching12

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.