Duqu 2.0 is a sophisticated modular Windows espionage platform discovered in 2015 and assessed as an evolution of the original Duqu malware lineage. It compromised Kaspersky Lab and systems associated with venues hosting P5+1 negotiations concerning Iran’s nuclear program, as well as other victims in Western countries, the Middle East, and Asia. The platform used multiple vulnerabilities, including CVE-2015-2360 to obtain kernel-mode execution, load unsigned kernel components, and tamper with security software in memory. It supported domain privilege escalation, pass-the-hash lateral movement, remotely deployed Windows Installer packages, process injection and migration, and kernel-level network traffic redirection. Its modular architecture included more than 100 observed plugins and supported command-and-control over web protocols, SMB named pipes, and custom TCP, including proxying and concealment of communications within image-like traffic. Duqu 2.0 employed encryption, compression, volatile execution, impersonation of security-product activity, and kernel data manipulation to evade detection. Public reporting has linked the operation to a highly resourced state-level espionage actor, but no definitive public attribution is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
DUQU 2.0: Main payload used 0day in win32k.sys for kernel execution (CVE-2015-2360). | Main payload used 0day in win32k.sys for kernel execution (CVE-2015-2360) ... Separate driver used for persistence in DMZ
5 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Duqu 2.0 is referenced as a nation-state malware platform that later implemented an idea similar to the HWFW bypass technique mentioned by the speaker.
Spyware that infected dozens of Kaspersky Lab machines in 2015; the article describes it as believed to be linked to Israel.
Cyber-espionage malware reported present on European hotel networks, used to support intelligence collection against high-value targets (e.g., negotiation participants).
Advanced targeted malware (APT-associated) reported in 2015, used in espionage-focused intrusions including infections at venues tied to Iran nuclear negotiations and a long-term compromise of Kaspersky Lab; described as using multiple zero-day exploits and assessed as requiring nation-state-level resources.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.