DUPERUNNER
DUPERUNNER is a previously undocumented Windows implant, described by Seqrite as a C++ second-stage payload, used in the spear-phishing campaign Operation DupeHike / DUPEHIKE tracked as UNG0902. The activity targeted Russian corporate employees, especially HR, payroll, internal administrative, finance, accounting, procurement, and legal functions, using bonus- and policy-themed lures delivered via spear-phishing. Observed infection chains used ZIP archives containing PDF-themed malicious LNK files; when executed, the LNK launched hidden PowerShell to download and run the DUPERUNNER payload, including from 46[.]149[.]71[.]230, saving it as s.exe in the victim Temp directory.
DUPERUNNER retrieves and opens a decoy PDF for user deception, including downloading a file disguised as fontawesome_tld.woff and saving it to the Temp directory with a timestamp-based filename before opening it. It then downloads an additional payload disguised as fontawesome.woff and injects shellcode into legitimate Windows processes such as explorer.exe, notepad.exe, and msedge.exe using VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread. The injected payload is an AdaptixC2 beacon/stager, and reporting states DUPERUNNER ultimately loads AdaptixC2 via process injection.
Associated reporting ties DUPERUNNER to Operation DupeHike / DUPEHIKE and threat cluster UNG0902. Seqrite noted infrastructure hosted under AS48282 (VDSINA-AS) and AS9123 (TIMEWEB-AS). AdaptixC2 traffic was observed using HTTP POST, including a /result endpoint, and Seqrite extracted configuration artifacts such as a Beacon-ID, User-Agent, and C2 URL/host. High-confidence observables directly mentioned in the reporting include 46[.]149[.]71[.]230, the ZIP name "Премия 2025.zip," the malicious shortcut "Документ_1_О_размере_годовой_премии.pdf.lnk," and the disguised payload names fontawesome_tld.woff and fontawesome.woff.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...use of malicious LNK file, leading to ... unknown implant, which we have dubbed as DUPERUNNER, which finally loads the AdaptixC2 Beacon...
Techniques & procedures
1 distinct technique documented for this family, organized by ATT&CK tactic.
Privilege Escalation
1 techniqueStealth
1 techniqueIOCs tracked for this family
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware used in the Operation DupeHike activity; no further functional details are provided in the content.
Previously undocumented implant used as a loader to execute the AdaptixC2 command-and-control beacon, enabling remote access and control via process injection.
Referenced as a malware payload delivered in Operation DUPEHIKE via process injection.
C++ second-stage implant downloaded/executed via malicious LNK + PowerShell. It re-downloads/opens a decoy PDF for user deception, enumerates target processes (explorer.exe/notepad.exe/msedge.exe), downloads the next-stage payload disguised as a .woff file, and injects the next-stage shellcode into a legitimate process via classic remote-thread process injection (VirtualAllocEx/WriteProcessMemory/CreateRemoteThread).
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.