ATT&CKCampaignsAPT41 DUST

APT41 DUST

C0040

Campaign, Jan 2023 to Jun 2024.View on attack.mitre.org

About this campaign

APT41 DUST was conducted by APT41 from 2023 to July 2024 against entities in Europe, Asia, and the Middle East. APT41 DUST targeted sectors such as shipping, logistics, and media for information gathering purposes. APT41 used previously-observed malware such as DUSTPAN as well as newly observed tools such as DUSTTRAP in APT41 DUST.

Techniques used23

Procedure examples23

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

APT41 DUST used encrypted payloads decrypted and executed in memory.

T1036.004
Masquerade Task or Service

APT41 DUST disguised DUSTPAN as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`.

T1070.004
File Deletion

APT41 DUST deleted various artifacts from victim systems following use.

T1071.001
Web Protocols

APT41 DUST used HTTPS for command and control.

T1074.001
Local Data Staging

APT41 DUST involved exporting data from Oracle databases to local CSV files prior to exfiltration.

T1102
Web Service

APT41 DUST used compromised Google Workspace accounts for command and control.

T1105
Ingress Tool Transfer

APT41 DUST involved execution of `certutil.exe` via web shell to download the DUSTPAN dropper.

T1119
Automated Collection

APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information.

T1213.006
Databases

APT41 DUST collected data from victim Oracle databases using SQLULDR2.

T1505.003
Web Shell

APT41 DUST involved use of web shells such as ANTSWORD and BLUEBEAM for persistence.

T1543.003
Windows Service

APT41 DUST used Windows Services with names such as `Windows Defend` for persistence of DUSTPAN.

T1553.002
Code Signing

APT41 DUST used stolen code signing certificates for DUSTTRAP malware and subsequent payloads.

T1560.001
Archive via Utility

APT41 DUST used `rar` to compress data downloaded from internal Oracle databases prior to exfiltration.

T1567.002
Exfiltration to Cloud Storage

APT41 DUST exfiltrated collected information to OneDrive.

T1569.002
Service Execution

APT41 DUST used Windows services to execute DUSTPAN.

View all 23 procedure examples

Attributed groups1

Software4

References1

  1. Google Cloud APT41 2024 Open source
    Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.