Dustman is a destructive wiper malware family associated with Iranian state-aligned operations and publicly linked to attacks against Bapco, Bahrain’s national oil company, in late 2019. It is widely described as a variant or successor of ZeroCleare and forms part of a broader cluster of Iranian disruptive tooling that also includes Shamoon-related tradecraft. Dustman has been tied in reporting to Iranian threat activity involving groups such as APT34/OilRig, although precise operator attribution is not uniformly established across all reporting.
Dustman is characterized as a Windows-focused wiper used against energy and industrial-sector targets in the Arabian Peninsula. Its purpose is destructive impact rather than espionage or monetization. Reporting consistently places it in campaigns intended to disrupt operations by rendering systems or data unusable. Like ZeroCleare and Shamoon-style attacks, Dustman is described as relying on modified or abused legitimate disk-access drivers to achieve low-level destructive effects, a technique used to bypass normal operating-system protections and directly damage storage structures.
Operationally, Dustman appears in the context of intrusions where Iranian operators first obtain enterprise access and then deploy destructive payloads at scale. Related reporting on the surrounding campaigns indicates that compromised remote-access infrastructure and exploitation of exposed enterprise services were important enabling factors for Iranian operations in this period, and that the same access ecosystems could support reconnaissance, persistence, and eventual activation of wipers such as Dustman. The malware has been discussed primarily in relation to the energy sector and other industrial environments, reflecting Iran’s established pattern of retaliatory or coercive disruptive cyber operations in the Middle East.
Dustman is best understood as a purpose-built wiper for destructive attacks on Windows enterprise environments, especially in energy and industrial networks, and as part of the evolution of Iran’s modern wiper arsenal from Shamoon through ZeroCleare and later disruptive families.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2019-2020, a couple new wipers – ZeroCleare and Dustman, were exposed in 2 operations against entities in the Arabian Peninsula.
In 2019-2020, a couple new wipers – ZeroCleare and Dustman, were exposed in 2 operations against entities in the Arabian Peninsula.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
VPN logs and other artifacts of the attack were then deleted in an attempt to obfuscate the attacker’s activities.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A successor to ZeroCleare, Dustman is a destructive wiper that uses modified legitimate drivers to achieve destructive effects.
An Iran-linked wiper malware family mentioned as part of a set of destructive tools designed to wipe data and disrupt operations.
Destructive wiper malware family referenced as part of Iran-aligned wiper tooling.
A destructive malware/wiper referenced in the report title.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.