DustySky, also referred to by its developer as NeD Worm, is a multi-stage Windows espionage malware family associated with the Molerats threat group, also known as the Gaza Cybergang. It has been active since at least May 2015 and has been used in politically motivated intelligence-gathering operations, primarily against targets in the Middle East. Reported victim sectors include government and diplomatic entities, aerospace and defense organizations, financial institutions, journalists, and software developers, with targeting also observed beyond the region.
DustySky is designed for surveillance and collection on compromised hosts. Documented capabilities include process discovery, screenshot capture, keylogging, removable-media and USB device detection, local staging of collected material in temporary directories, and exfiltration of stolen data to command-and-control infrastructure. It also performs security software discovery, including checks for antivirus products, and uses Windows Management Instrumentation in at least part of its infection chain to gather operating system and defensive-product information.
The malware establishes persistence through a Windows Registry Run autostart entry under the current user context. It includes cleanup functionality and can delete files it creates on the infected system. DustySky also incorporates command-and-control resilience through multiple hard-coded servers, attempting an alternate server if the primary one is unavailable.
Operational reporting links DustySky to targeted phishing activity using malicious emails and themed lure content in Hebrew, Arabic, or English, consistent with Molerats tradecraft. The malware’s overall role is that of a custom surveillance implant supporting long-term collection and exfiltration in regional cyber-espionage campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DustySky (called “NeD Worm” by its developer) is a multi-stage malware in use since May 2015. It is in use by the Molerats (aka Gaza cybergang), a politically motivated group whose main objective, we believe, is intelligence gathering.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
In one case, the attackers used stolen email credentials and logged in from 96.44.156.201, potentially their proxy or VPN endpoint.
DustySky Core is a Trojan backdoor... Searching for removable media and network drives, and duplicating itself into them.
IP address 45.32.13.169 and all the domains that are pointing to it host a webpage which is a copy of a legitimate and unrelated software website - iMazing... the version on the fake website is bundled with DustySky malware.
Based on dozens of known attacks and the vast infrastructure in use – we estimate that a wave of targeted malicious email messages has been sent on a weekly basis. These attacks are targeted, but not spear-phished.
The dropper uses Windows Management Instrumentation to extract information about the operating system and whether an antivirus is active.
If the victim extracts the archive and clicks the .exe file, the lure document or video are presented while the computer is being infected with DustySky. | In recent samples the group used Microsoft Word files embed with a malicious macro, which would infect the victim if enabled. Note, that these infection methods rely on social engineering - convincing the victim to open the file (and enabling content if it is disabled) - and not on software vulnerabilities.
In one case, the attackers used stolen email credentials and logged in from 96.44.156.201, potentially their proxy or VPN endpoint.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
In one case, the attackers used stolen email credentials and logged in from 96.44.156.201, potentially their proxy or VPN endpoint.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The dropper uses the following function to obfuscate the name of functions and other parts of the malware (In later versions, SmartAssembly 6.9.0.114 .NET obfuscator was used).
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The dropper uses Windows Management Instrumentation to extract information about the operating system and whether an antivirus is active.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
For VM evasion the dropper checks whether there is a DLL that indicate that the malware is running in a virtual machine... If the dropper is indeed running in a virtual machine, it will open the lure document and stop its activity.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
DustySky has two hardcoded domains of command and control servers. It starts by checking if the first one is alive by sending a GET request to TEST.php or index.php, expecting “OK” as response.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
227 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used by Molerats to stage and archive collected files prior to exfiltration.
Malware that exfiltrates data to its C2 server.
Malware that persists by creating a Run registry entry under HKCU.
Malware with two hard-coded C2 domains and simple failover between them.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.