DUSTPAN is a Windows in-memory dropper written in C/C++ and associated with APT41, a China-nexus espionage threat actor. It decrypts and executes embedded payloads, including ChaCha20-encrypted BEACON payloads, in memory. Variants can also load an encrypted external payload from disk. The decrypted payload may be injected into another process or executed in a new thread within DUSTPAN’s own process space. APT41 has used DUSTPAN in campaigns against media and entertainment organizations in Asia and in broader espionage operations, including activity involving Oracle-database data theft. Operators have disguised DUSTPAN as legitimate-looking Windows binaries and established persistence and execution through masqueraded Windows services. Its encrypted in-memory payload handling, process injection capability, service-based persistence, and masquerading support stealthy deployment of follow-on backdoors and command-and-control implants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DUSTPAN is an in-memory dropper that decrypts and executes an embedded payload and may be injected into another process or spawn on its own. It loads encrypted BEACON payloads into memory and was made persistent through a masqueraded Windows service.
APT41 DUST used Windows Services with names such as Windows Defend for persistence of DUSTPAN. DUSTPAN can persist as a Windows Service in operations.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
"DUSTPAN is an in-memory dropper that decrypts and executes an embedded payload" and "DUSTTRAP... decrypts its Portable Executable (PE) file to execute in memory."
APT41 disguised DUSTPAN as a Windows binary by executing the malicious file as w3wp.exe or conn.exe.
DUSTPAN was disguised as a Windows binary by executing as "w3wp.exe" or "conn.exe" and used a service named "Windows Defend."
"DUSTPAN... may be injected into another process or spawn on its own."
DUSTPAN is an in-memory dropper written in C/C++ that decrypts and executes an embedded payload.
The BEACON payloads, once executed, communicated using either self-managed infrastructure hosted behind Cloudflare or utilized Cloudflare Workers as their command-and-control (C2) channels.
DUSTPAN loads BEACON into memory and, once executed, it communicates with its configured C2 server; the ATT&CK table lists Web Protocols for Command and Control.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an APT41-associated tool similar to Amaranth Loader.
Referenced as an APT41-associated tool similar to Amaranth Loader; specific functionality not described in the provided content.
Listed as a tool used by the BRONZE ATLAS threat profile.
DUSTPAN is a backdoor used by APT41 for command and control and persistent access in targeted cyberespionage operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.