RegDuke - S0511 (47124daf-44be-4530-9c63-038bc64318dd)
RegDuke is a first stage implant written in .NET and used by APT29 since at least 2017. RegDuke has been used to control a compromised machine when control of other implants on the machine was lost.(Citation: ESET Dukes October 2019)