DUSTPAN

S1158

Malware.View on attack.mitre.org

About this malware

DUSTPAN is an in-memory dropper written in C/C++ used by APT41 since 2021 that decrypts and executes an embedded payload.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027.009
Embedded Payloads

DUSTPAN decrypts and executes an embedded payload.

T1027.013
Encrypted/Encoded File

DUSTPAN decrypts an embedded payload.

T1036.005
Match Legitimate Resource Name or Location

DUSTPAN is often disguised as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`.

T1055.002
Portable Executable Injection

DUSTPAN can inject its decrypted payload into another process.

T1140
Deobfuscate/Decode Files or Information

DUSTPAN decodes and decrypts embedded payloads.

T1543.003
Windows Service

DUSTPAN can persist as a Windows Service in operations.

Groups that use it1

Campaigns1

References2

  1. Google Cloud APT41 2022 Open source
    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman & John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved September 16, 2024.
  2. Google Cloud APT41 2024 Open source
    Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.