Operation Dust Storm is a named intrusion campaign associated with targeted espionage activity. Reported tradecraft includes watering-hole compromise of a popular software reseller to exploit the then-zero-day Internet Explorer vulnerability CVE-2014-0322 for initial access, use of operational domain infrastructure, execution of JavaScript through mshta.exe as a living-off-the-land technique, and masquerading of executables as image files for defense evasion. The operation also deployed Android backdoors that collected and exfiltrated data from infected mobile devices, including attacker-selected files, SMS messages, and call information, forwarding the stolen data to command-and-control infrastructure. The observed combination of strategic web compromise, stealthy execution, masquerading, and mobile surveillance capabilities is consistent with a focused intelligence-collection campaign.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
During Operation Dust Storm, the threat actors exploited ... Microsoft Windows Help vulnerability CVE-2010-1885
APT12 has exploited ... vulnerabilities in Adobe Reader and Flash (CVE-2009-4324, CVE-2009-0927, CVE-2011-0609, CVE-2011-0611).
During Operation Dust Storm ... Internet Explorer vulnerabilities, including CVE-2011-1255
Axiom has used exploits for multiple vulnerabilities including ... CVE-2012-1889
Axiom has used exploits for multiple vulnerabilities including CVE-2014-0322, CVE-2012-4792, CVE-2012-1889, and CVE-2013-3893.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actors in Operation Dust Storm used Android backdoors to exfiltrate specific files from infected devices.
Activity cluster associated with use of Android backdoors to exfiltrate specific files from infected devices.
Threat activity cluster associated here with use of Android backdoors to exfiltrate specific files from infected mobile devices.
Activity cluster involving Android backdoors used to collect and send victim mobile device information and data to command-and-control servers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.