logo

Operation DupeHike Attacking Employees Using Weaponized Documents DUPERUNNER Malware

ID: 50bdce89-5571-5221-a6b6-6a18d987211c

STIX ID: report--50bdce89-5571-5221-a6b6-6a18d987211c

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Operation DupeHike is a targeted phishing campaign attributed to UNG0902 that uses ZIP-embedded .LNK shortcuts to execute PowerShell and download a C++ implant (DUPERUNNER) which performs reconnaissance and injection to deploy an AdaptixC2 HTTP beacon; the campaign targets HR/payroll personnel in Russian corporate environments and uses infrastructure identified at IP 46.149.71.230 and ASNs 48282/9123.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.