ATT&CKCampaignsOperation Dust Storm

Operation Dust Storm

C0016

Campaign, Jan 2010 to Feb 2016.View on attack.mitre.org

About this campaign

Operation Dust Storm was a long-standing persistent cyber espionage campaign that targeted multiple industries in Japan, South Korea, the United States, Europe, and several Southeast Asian countries. By 2015, the Operation Dust Storm threat actors shifted from government and defense-related intelligence targets to Japanese companies or Japanese subdivisions of larger foreign organizations supporting Japan's critical infrastructure, including electricity generation, oil and natural gas, finance, transportation, and construction.

Operation Dust Storm threat actors also began to use Android backdoors in their operations by 2015, with all identified victims at the time residing in Japan or South Korea.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1027.002
Software Packing

For Operation Dust Storm, the threat actors used UPX to pack some payloads.

T1027.013
Encrypted/Encoded File

During Operation Dust Storm, the threat actors encoded some payloads with a single-byte XOR, both skipping the key itself and zeroing in an attempt to avoid exposing the key; other payloads were Base64-encoded.

T1036
Masquerading

For Operation Dust Storm, the threat actors disguised some executables as JPG files.

T1059.005
Visual Basic

During Operation Dust Storm, the threat actors used Visual Basic scripts.

T1059.007
JavaScript

During Operation Dust Storm, the threat actors used JavaScript code.

T1140
Deobfuscate/Decode Files or Information

During Operation Dust Storm, attackers used VBS code to decode payloads.

T1189
Drive-by Compromise

During Operation Dust Storm, the threat actors used a watering hole attack on a popular software reseller to exploit the then-zero-day Internet Explorer vulnerability CVE-2014-0322.

T1203
Exploitation for Client Execution

During Operation Dust Storm, the threat actors exploited Adobe Flash vulnerability CVE-2011-0611, Microsoft Windows Help vulnerability CVE-2010-1885, and several Internet Explorer vulnerabilities, including CVE-2011-1255, CVE-2012-1889, and CVE-2014-0322.

T1204.001
Malicious Link

During Operation Dust Storm, the threat actors relied on a victim clicking on a malicious link sent via email.

T1204.002
Malicious File

During Operation Dust Storm, the threat actors relied on potential victims to open a malicious Microsoft Word document sent via email.

T1218.005
Mshta

During Operation Dust Storm, the threat actors executed JavaScript code via `mshta.exe`.

T1518
Software Discovery

During Operation Dust Storm, the threat actors deployed a file called `DeployJava.js` to fingerprint installed software on a victim system prior to exploit delivery.

T1566.001
Spearphishing Attachment

During Operation Dust Storm, the threat actors sent spearphishing emails that contained a malicious Microsoft Word document.

T1566.002
Spearphishing Link

During Operation Dust Storm, the threat actors sent spearphishing emails containing a malicious link.

T1568
Dynamic Resolution

For Operation Dust Storm, the threat actors used dynamic DNS domains from a variety of free providers, including No-IP, Oray, and 3322.

View all 17 procedure examples

Attributed groups0

MITRE does not attribute this campaign to a group.

Software6

References1

  1. Cylance Dust Storm Open source
    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.