Campaign, Jan 2010 to Feb 2016.View on attack.mitre.org
Operation Dust Storm was a long-standing persistent cyber espionage campaign that targeted multiple industries in Japan, South Korea, the United States, Europe, and several Southeast Asian countries. By 2015, the Operation Dust Storm threat actors shifted from government and defense-related intelligence targets to Japanese companies or Japanese subdivisions of larger foreign organizations supporting Japan's critical infrastructure, including electricity generation, oil and natural gas, finance, transportation, and construction.
Operation Dust Storm threat actors also began to use Android backdoors in their operations by 2015, with all identified victims at the time residing in Japan or South Korea.
| Technique | Procedure example |
|---|---|
| T1027.002 Software Packing |
For Operation Dust Storm, the threat actors used UPX to pack some payloads. |
| T1027.013 Encrypted/Encoded File |
During Operation Dust Storm, the threat actors encoded some payloads with a single-byte XOR, both skipping the key itself and zeroing in an attempt to avoid exposing the key; other payloads were Base64-encoded. |
| T1036 Masquerading |
For Operation Dust Storm, the threat actors disguised some executables as JPG files. |
| T1059.005 Visual Basic |
During Operation Dust Storm, the threat actors used Visual Basic scripts. |
| T1059.007 JavaScript |
During Operation Dust Storm, the threat actors used JavaScript code. |
| T1140 Deobfuscate/Decode Files or Information |
During Operation Dust Storm, attackers used VBS code to decode payloads. |
| T1189 Drive-by Compromise |
During Operation Dust Storm, the threat actors used a watering hole attack on a popular software reseller to exploit the then-zero-day Internet Explorer vulnerability CVE-2014-0322. |
| T1203 Exploitation for Client Execution |
During Operation Dust Storm, the threat actors exploited Adobe Flash vulnerability CVE-2011-0611, Microsoft Windows Help vulnerability CVE-2010-1885, and several Internet Explorer vulnerabilities, including CVE-2011-1255, CVE-2012-1889, and CVE-2014-0322. |
| T1204.001 Malicious Link |
During Operation Dust Storm, the threat actors relied on a victim clicking on a malicious link sent via email. |
| T1204.002 Malicious File |
During Operation Dust Storm, the threat actors relied on potential victims to open a malicious Microsoft Word document sent via email. |
| T1218.005 Mshta |
During Operation Dust Storm, the threat actors executed JavaScript code via `mshta.exe`. |
| T1518 Software Discovery |
During Operation Dust Storm, the threat actors deployed a file called `DeployJava.js` to fingerprint installed software on a victim system prior to exploit delivery. |
| T1566.001 Spearphishing Attachment |
During Operation Dust Storm, the threat actors sent spearphishing emails that contained a malicious Microsoft Word document. |
| T1566.002 Spearphishing Link |
During Operation Dust Storm, the threat actors sent spearphishing emails containing a malicious link. |
| T1568 Dynamic Resolution |
For Operation Dust Storm, the threat actors used dynamic DNS domains from a variety of free providers, including No-IP, Oray, and 3322. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.