DustySky

ClearSky. (2016, January 7). Operation DustySky. Retrieved January 8, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareDustySky

DustySky has two hard-coded domains for C2 servers; if the first does not respond, it will try the second.

T1027
Obfuscated Files or Information
MalwareDustySky

The DustySky dropper uses a function to obfuscate the name of functions and other parts of the malware.

T1047
Windows Management Instrumentation
MalwareDustySky

The DustySky dropper uses Windows Management Instrumentation to extract information about the operating system and whether an anti-virus is active.

T1056.001
Keylogging
MalwareDustySky

DustySky contains a keylogger.

T1057
Process Discovery
MalwareDustySky

DustySky collects information about running processes from victims.

T1057
Process Discovery
GroupMolerats

Molerats actors obtained a list of active processes on the victim and sent them to C2 servers.

T1071.001
Web Protocols
MalwareDustySky

DustySky has used both HTTP and HTTPS for C2.

T1082
System Information Discovery
MalwareDustySky

DustySky extracts basic information about the operating system.

T1083
File and Directory Discovery
MalwareDustySky

DustySky scans the victim for files that contain certain keywords and document types including PDF, DOC, DOCX, XLS, and XLSX, from a list that is obtained from the C2 as a text file. It can also identify logical drives for the infected machine.

T1091
Replication Through Removable Media
MalwareDustySky

DustySky searches for removable media and duplicates itself onto it.

T1518.001
Security Software Discovery
MalwareDustySky

DustySky checks for the existence of anti-virus.

T1547.001
Registry Run Keys / Startup Folder
MalwareDustySky

DustySky achieves persistence by creating a Registry entry in HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

T1555.003
Credentials from Web Browsers
GroupMolerats

Molerats used the public tool BrowserPasswordDump10 to dump passwords saved in browsers on victims.

T1570
Lateral Tool Transfer
MalwareDustySky

DustySky searches for network drives and removable media and duplicates itself onto them.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.