DustySky

S0062

Malware.View on attack.mitre.org

About this malware

DustySky is multi-stage malware written in .NET that has been used by Molerats since May 2015.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1008
Fallback Channels

DustySky has two hard-coded domains for C2 servers; if the first does not respond, it will try the second.

T1027
Obfuscated Files or Information

The DustySky dropper uses a function to obfuscate the name of functions and other parts of the malware.

T1041
Exfiltration Over C2 Channel

DustySky has exfiltrated data to the C2 server.

T1047
Windows Management Instrumentation

The DustySky dropper uses Windows Management Instrumentation to extract information about the operating system and whether an anti-virus is active.

T1056.001
Keylogging

DustySky contains a keylogger.

T1057
Process Discovery

DustySky collects information about running processes from victims.

T1070.004
File Deletion

DustySky can delete files it creates from the infected system.

T1071.001
Web Protocols

DustySky has used both HTTP and HTTPS for C2.

T1074.001
Local Data Staging

DustySky created folders in temp directories to host collected files before exfiltration.

T1082
System Information Discovery

DustySky extracts basic information about the operating system.

T1083
File and Directory Discovery

DustySky scans the victim for files that contain certain keywords and document types including PDF, DOC, DOCX, XLS, and XLSX, from a list that is obtained from the C2 as a text file. It can also identify logical drives for the infected machine.

T1091
Replication Through Removable Media

DustySky searches for removable media and duplicates itself onto it.

T1113
Screen Capture

DustySky captures PNG screenshots of the main screen.

T1120
Peripheral Device Discovery

DustySky can detect connected USB devices.

T1518
Software Discovery

DustySky lists all installed software for the infected machine.

View all 19 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. DustySky Open source
    ClearSky. (2016, January 7). Operation DustySky. Retrieved January 8, 2016.
  2. DustySky2 Open source
    ClearSky Cybersecurity. (2016, June 9). Operation DustySky - Part 2. Retrieved August 3, 2016.
  3. Kaspersky MoleRATs April 2019 Open source
    GReAT. (2019, April 10). Gaza Cybergang Group1, operation SneakyPastes. Retrieved May 13, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.