Campaign, Jan 2023 to Jun 2024.View on attack.mitre.org
APT41 DUST was conducted by APT41 from 2023 to July 2024 against entities in Europe, Asia, and the Middle East. APT41 DUST targeted sectors such as shipping, logistics, and media for information gathering purposes. APT41 used previously-observed malware such as DUSTPAN as well as newly observed tools such as DUSTTRAP in APT41 DUST.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
APT41 DUST used encrypted payloads decrypted and executed in memory. |
| T1036.004 Masquerade Task or Service |
APT41 DUST disguised DUSTPAN as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`. |
| T1070.004 File Deletion |
APT41 DUST deleted various artifacts from victim systems following use. |
| T1071.001 Web Protocols |
APT41 DUST used HTTPS for command and control. |
| T1074.001 Local Data Staging |
APT41 DUST involved exporting data from Oracle databases to local CSV files prior to exfiltration. |
| T1102 Web Service |
APT41 DUST used compromised Google Workspace accounts for command and control. |
| T1105 Ingress Tool Transfer |
APT41 DUST involved execution of `certutil.exe` via web shell to download the DUSTPAN dropper. |
| T1119 Automated Collection |
APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information. |
| T1213.006 Databases |
APT41 DUST collected data from victim Oracle databases using SQLULDR2. |
| T1505.003 Web Shell |
APT41 DUST involved use of web shells such as ANTSWORD and BLUEBEAM for persistence. |
| T1543.003 Windows Service |
APT41 DUST used Windows Services with names such as `Windows Defend` for persistence of DUSTPAN. |
| T1553.002 Code Signing |
APT41 DUST used stolen code signing certificates for DUSTTRAP malware and subsequent payloads. |
| T1560.001 Archive via Utility |
APT41 DUST used `rar` to compress data downloaded from internal Oracle databases prior to exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
APT41 DUST exfiltrated collected information to OneDrive. |
| T1569.002 Service Execution |
APT41 DUST used Windows services to execute DUSTPAN. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.