DUSTTRAP

S1159

Malware.View on attack.mitre.org

About this malware

DUSTTRAP is a multi-stage plugin framework associated with APT41 operations with multiple components.

Techniques used29

Procedure examples29

TechniqueProcedure example
T1005
Data from Local System

DUSTTRAP can gather data from infected systems.

T1010
Application Window Discovery

DUSTTRAP can enumerate running application windows.

T1012
Query Registry

DUSTTRAP can enumerate Registry items.

T1016
System Network Configuration Discovery

DUSTTRAP can enumerate infected system network information.

T1018
Remote System Discovery

DUSTTRAP can use `ping` to identify remote hosts within the victim network.

T1027.009
Embedded Payloads

DUSTTRAP contains additional embedded DLLs and configuration files that are loaded into memory during execution.

T1027.013
Encrypted/Encoded File

DUSTTRAP begins with an initial launcher that decrypts an AES-128-CFB encrypted file on disk and executes it in memory.

T1041
Exfiltration Over C2 Channel

DUSTTRAP can exfiltrate collected data over C2 channels.

T1055
Process Injection

DUSTTRAP compromises the `.text` section of a legitimate system DLL in `%windir%` to hold the contents of retrieved plug-ins.

T1056.001
Keylogging

DUSTTRAP can perform keylogging operations.

T1057
Process Discovery

DUSTTRAP can enumerate running processes.

T1059.003
Windows Command Shell

DUSTTRAP can execute commands via `cmd.exe`.

T1070
Indicator Removal

DUSTTRAP restores the `.text` section of compromised DLLs after malicious code is loaded into memory and before the file is closed.

T1070.005
Network Share Connection Removal

DUSTTRAP can remove network shares from infected systems.

T1082
System Information Discovery

DUSTTRAP reads the value of the infected system's `HKLM\SYSTEM\Microsoft\Cryptography\MachineGUID` value.

View all 29 procedure examples

Groups that use it1

Campaigns1

References1

  1. Google Cloud APT41 2024 Open source
    Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.