APTMembers
APT

APT29's 2013 MiniDuke Implant Still Beaconing via Aftermarket Domain in 2026

A MiniDuke Stage 3 trojan attributed to APT29 continues to beacon through 34 parameterised PHP endpoints on a repurposed aftermarket domain, leveldelta.com, with its TLS certificate renewed as recently as May 2026. The implant deploys a three-layer anti-analysis stack—CPU-clock timing checks, debugger detection, and extended sleep intervals—that successfully deceived one of only two sandboxes that processed it. A toolchain first publicly documented in 2013 remains an active espionage instrument targeting Hong Kong more than a decade later.

Jun 26, 2026, 20:56 (UTC+9)Last seenJun 26, 2026Severity77ByCTX TeamActorAPT29MinidionisIOC36MITRE12RegionsHK

Sixty-three of 76 antivirus engines correctly identify the 326-kilobyte Windows executable bearing SHA-256 05e4224d4dd4e5fbd381ed33edb5bf847fbc138fbe9f57cb7d1f8fc9fa9a382d as a MiniDuke Stage 3 trojan — yet one of only two sandboxes that processed it returned a 97-percent-confidence verdict of harmless. That split is not a data anomaly. It is the point.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence