PINEGROVE is a tool used by the APT41 DUST cluster to gather local system and database information on compromised hosts. The provided content associates it with Oracle database-focused intrusions in which APT41 DUST used tools including SQLULDR2 and PINEGROVE for information collection. In the same activity, the actor collected data from victim Oracle databases, exported database contents to local CSV files, compressed data with RAR, and exfiltrated the collected information to OneDrive. The broader intrusion set used HTTPS command and control via infrastructure behind Cloudflare or Cloudflare Workers, compromised Google Workspace accounts for C2, web shells such as ANTSWORD and BLUEBEAM, and malware including DUSTPAN and DUSTTRAP. High-confidence attribution in the content links PINEGROVE specifically to APT41 DUST and to collection of local system and database information; no additional technical details or indicators of compromise for PINEGROVE itself are provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information.
1 distinct technique documented for this family, organized by ATT&CK tactic.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used by APT41 (DUST) for local system and database information collection during intrusions.
Tool used to gather local system and database information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.