When the Duqu command and control is operating over HTTP or HTTPS, Duqu uploads data to its controller by appending it to a blank JPG file.2
tool
Duqu S0038
- Type
- malware
- Platform
- Windows
- Created
- 31 May 2017
- Last modified
- 16 April 2025
Duqu is a malware platform that uses a modular approach to extend functionality after deployment within a target network. [1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S0038
The discovery modules used with Duqu can collect information on open windows.3
The reconnaissance modules used with Duqu can collect information on network configuration.4
Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware.5
The discovery modules used with Duqu can collect information on network connections.6
Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware.7
Standing S0038
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
82nd percentile · 82% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
94th percentile · 94% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
21st percentile · 79% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S0038
468 distinct rules cover the 21 techniques recorded for this tool. The 497 technique-to-rule mappings resolve to 468 distinct rules, because one rule can cover several techniques. 310 Sigma · 158 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org