Skip to content
ThreatCluster

Operation DupeHike: DuperRunner Malware Targets Russian Corporate Employees

First seen 4 Dec 2025, 11:44 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

Operation DupeHike is a sophisticated cyber attack campaign targeting employees in Russian corporate environments, particularly in human resources, payroll, and administrative departments. The campaign, attributed to the threat group UNG0902, employs weaponized documents themed around employee bonuses to deliver the DuperRunner malware, which is previously unknown.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 193d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Ung0902 and DuperRunner in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed