PINEGROVE is a Windows data-transfer utility used by the China-nexus APT41 (DUST) intrusion cluster to copy large volumes of sensitive information from compromised enterprise networks to Microsoft OneDrive for exfiltration and subsequent analysis. It has been observed alongside SQLULDR2 in espionage operations, including activity targeting media and entertainment organizations in Asia and victims in other sectors. PINEGROVE supports collection and staging of locally available system and database data for theft via a legitimate cloud-storage service.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
They used PINEGROVE to efficiently copy large volumes of sensitive information from compromised networks, transferring to OneDrive for further exfiltration and analysis.
APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used by APT41 (DUST) for local system and database information collection during intrusions.
Tool used to gather local system and database information.
A tool used to copy large volumes of sensitive data from compromised networks and stage or transfer it to OneDrive for exfiltration and analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.