logo

Operation DupeHike : UNG0902 targets Russian employees with DUPERUNNER and AdaptixC2

ID: 09340d26-9b51-5001-9a22-69ab06d08e0b

STIX ID: report--09340d26-9b51-5001-9a22-69ab06d08e0b

Feed Name: Seqrite Blog

Threat Score
75/100

Date Published: 2025-12-03

Date Updated: 2026-04-30

Author: Subhajeet Singha

...
...

SEQRITE analysts describe a multi-stage espionage campaign targeting Russian corporate HR and payroll staff: spear-phishing ZIPs contained malicious LNK shortcuts that launch PowerShell to fetch a C++ implant (DUPERUNNER), which performs process injection to load an AdaptixC2 beacon. The report provides technical breakdowns of each stage, extracted IOCs (multiple SHA-256 hashes, IP 46.149.71.230, domains, and C2 details), infrastructure analysis, MITRE ATT&CK mappings, and detection names used by SEQRITE.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.