DUSTPAN is an APT41-associated in-memory dropper/loader written in C/C++ that decrypts and executes embedded payloads. Variants can also load an external payload from disk using a hard-coded file path encrypted in the PE file. Observed execution behavior includes decrypting payloads and either injecting them into another process or running them in a new thread within the current process. DUSTPAN has been disguised as legitimate Windows binaries such as w3wp.exe or conn.exe, and APT41 DUST has used Windows services for persistence and execution, including a service named "Windows Defend." In observed intrusions, APT41 used certutil.exe via web shells to download the DUSTPAN dropper, then used DUSTPAN to load BEACON payloads into memory. Those BEACON payloads were reported as ChaCha20-encrypted and communicated with command-and-control infrastructure hosted behind Cloudflare or via Cloudflare Workers. The malware is directly associated with APT41 / APT41 DUST activity, including 2021 and 2022 breaches and later investigations. In broader reporting, DUSTPAN has also been referenced by the alias StealthVector and noted as similar to other APT41 tooling such as DUSTTRAP and DodgeBox. The content further places DUSTPAN in campaigns involving ANTSWORD and BLUEBEAM web shells, SQLULDR2 and PINEGROVE for collection, and exfiltration of sensitive data to Microsoft OneDrive.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT41 DUST used Windows Services with names such as Windows Defend for persistence of DUSTPAN. DUSTPAN can persist as a Windows Service in operations.
DUSTPAN is an in-memory dropper written in C/C++ that decrypts and executes an embedded payload. Different variations of DUSTPAN may also load an external payload off disk from a hard-coded file path encrypted in the Portable Executable (PE) file.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change.
Akira has used legitimate names and locations for files to evade defenses.
DUSTPAN may be configured to inject the decrypted payload into another process or create a new thread and execute it within its own process space.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an APT41-associated tool similar to Amaranth Loader.
Referenced as an APT41-associated tool similar to Amaranth Loader; specific functionality not described in the provided content.
DUSTPAN is a backdoor used by APT41 for command and control and persistent access in targeted cyberespionage operations.
Decrypts and executes an embedded payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.