Duqu is a nation-state espionage platform discovered in 2011, closely related to Stuxnet, built for intelligence collection and reconnaissance; its 2015 successor Duqu 2.0 targeted venues of the P5+1 Iran nuclear negotiations and security firms — tying the operation directly to MENA-focused strategic espionage.
Duqu was disclosed in October 2011 by Hungary's CrySyS Lab and Symantec, which found it shared substantial code with Stuxnet (the 'Tilded' platform), indicating a common nation-state author widely assessed as U.S./Israel-linked. In June 2015 Kaspersky exposed Duqu 2.0 after discovering it inside its own network. Attribution is high confidence on capability and lineage but circumstantial and officially unconfirmed on the specific sponsor — preserved here; Duqu has no MITRE Group ID (catalogued as malware).
Duqu's mission was reconnaissance and espionage rather than sabotage: it collected system information, keystrokes, and credentials to enable follow-on operations, and used stolen digital certificates and modular components for stealth. Duqu 2.0 was notably advanced, operating almost entirely in memory to minimize forensic footprint, exploiting zero-days for lateral movement, and hiding C2 in network appliance firmware.
MENA relevance is direct and strategic. Duqu 2.0's victims included hotels and venues hosting the P5+1 (Iran nuclear deal) negotiations, alongside targets connected to the 70th-anniversary events of Auschwitz liberation and security vendors — espionage centered on the Iranian nuclear dossier. The original Duqu's reconnaissance role is likewise assessed as preparation for Stuxnet-class operations against Iran's nuclear program.
No Duqu activity has been reported since the 2015 Duqu 2.0 exposure; it is assessed as retired. It is included as an attribution-sensitive Stuxnet-family espionage platform with clear Iran/MENA strategic targeting, flagged circumstantial on sponsor.