Kaspersky researchers reported that the Duqu espionage platform continued to evolve after its initial discovery, identifying additional malware components and operational links tied to the broader campaign. The report highlighted newly observed elements dubbed Mr. B. Jason and Dexter, which appeared to extend the toolkit used by the attackers for stealthy intrusion, persistence, and intelligence collection on targeted systems.
The findings reinforced that Duqu was not a single isolated malware sample but a modular, actively maintained operation with multiple moving parts and likely dedicated operators. By connecting these components to the wider Duqu ecosystem, the research showed that the threat actors were refining their capabilities and sustaining a long-term cyber-espionage effort against selected victims.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Securelist published technical analysis of the Duqu 2.0 persistence module, revealing implementation details of how the malware maintained access on compromised systems. This was a distinct disclosure predating later 2021 reporting on continued Duqu activity.
Kaspersky researchers disclosed that a core Duqu payload DLL framework appeared to be written in an unidentified object-oriented, event-driven language rather than standard C++. The company said the unusual framework hindered analysis and suggested a highly sophisticated, possibly nation-state-backed development effort.
Securelist published a report titled "The Duqu Saga Continues: Enter Mr. B. Jason and TV’s Dexter," indicating ongoing analysis and new technical details related to the Duqu malware campaign.
McAfee Labs reported that Duqu was closely related to Stuxnet but built for espionage, targeting a small number of organizations including certificate authorities and other key sites. The analysis described signed and unsigned drivers, encrypted modules, command-and-control infrastructure in India, and capabilities such as remote module installation and antivirus evasion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourcesecurelist.com
Open sourcetechspot.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.