RegDuke is a Windows first-stage implant associated with APT29, also known as the Dukes or Cozy Bear, and has been used since at least 2017 in long-running cyberespionage activity including Operation Ghost. It functions as a recovery-stage component within a multi-stage intrusion platform that also included PolyglotDuke, MiniDuke, and FatDuke. The malware is written in .NET and is designed to maintain footholds and enable follow-on execution while blending with legitimate system activity.
RegDuke uses Dropbox for command-and-control communications. It stores an encrypted payload on disk and keeps the corresponding encryption key in the Windows Registry, including under seemingly legitimate Registry keys, and can also rely on hardcoded material for string decryption. The malware is capable of extracting and executing PowerShell scripts received through command-and-control traffic, giving operators a flexible mechanism for post-compromise tasking and payload delivery.
For persistence, RegDuke can use a WMI consumer configured to launch when a specific process starts, providing a stealthy event-driven execution mechanism. Its observed use aligns with APT29 tradecraft focused on covert persistence, staged malware deployment, and resilient access in high-value espionage targets. Operation Ghost victimology included diplomatic and government entities, particularly ministries of foreign affairs and embassy environments in Europe and North America.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RegDuke, a recovery first stage, which uses Dropbox as its C&C server. The main payload is encrypted on disk and the encryption key is stored in the Windows registry.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence T1053 Scheduled Task The Dukes use Scheduled Task to launch malware at startup.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
Persistence T1053 Scheduled Task The Dukes use Scheduled Task to launch malware at startup.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
Multiple actors and tools (e.g., APT29, APT33, FIN8, Turla, Blue Mockingbird, PoshC2, POSHSPY, RegDuke, SeaDuke) are described as using WMI event subscriptions/filters/consumers to establish persistence, including triggering at system boot or on specific process start (e.g., WINWORD.EXE).
Persistence T1053 Scheduled Task The Dukes use Scheduled Task to launch malware at startup.
Multiple actors and tools (e.g., APT29, APT33, FIN8, Turla, Blue Mockingbird, PoshC2, POSHSPY, RegDuke, SeaDuke) are described as using WMI event subscriptions/filters/consumers to establish persistence, including triggering at system boot or on specific process start (e.g., WINWORD.EXE).
The Dukes encrypts PolyglotDuke and LiteDuke payloads with custom algorithms. They also rely on known obfuscation techniques such as opaque predicates and control flow flattening to obfuscate RegDuke, MiniDuke and FatDuke.
Command and Control T1001 Data Obfuscation The Dukes use steganography to hide payloads and commands inside valid images.
Command and Control T1008 Fallback Channels The Dukes have multiple C&C servers in case one of them is down.
Command and Control T1071 Standard Application Layer Protocol The Dukes are using HTTP and HTTPS protocols to communicate with the C&C server.
Command and Control T1090 Connection Proxy The Dukes can communicate to the C&C server via proxy. They also use named pipes as proxies when a machine is isolated within a network and does not have direct access to the internet.
PolyglotDuke fetches public webpages (Twitter, Reddit, Imgur, etc.) to get encrypted strings leading to new C&C server. For RegDuke, they also use Dropbox as a C&C server.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Their toolkit includes ... QUIETEXIT, RAINDROP, RegDuke, reGeorg, Rubeus...
Malware that extracts and executes PowerShell scripts received via C2.
APT29 malware strain used in Operation Ghost.
Malware that decrypts strings using a registry-stored or hardcoded key.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.