DUST is an APT41-associated intrusion cluster/malware set observed in campaigns targeting Oracle database environments. Reported tradecraft includes command and control over HTTPS, including infrastructure hosted behind Cloudflare or implemented with Cloudflare Workers, as well as use of compromised Google Workspace accounts for C2. Persistence and execution involved web shells such as ANTSWORD and BLUEBEAM, use of certutil.exe via a web shell to download the DUSTPAN dropper, and Windows Services for persistence and execution of DUSTPAN, including masqueraded service names such as "Windows Defend." DUSTPAN was disguised as legitimate Windows binaries such as w3wp.exe or conn.exe. Related payload execution included DLL search order hijacking and DLL side-loading to execute DUSTTRAP via an AhnLab uninstaller. Components including DUSTTRAP and subsequent payloads were signed with stolen code-signing certificates, and encrypted payloads were decrypted and executed in memory. Collection activity included use of SQLULDR2 and PINEGROVE to gather local system and database information, extraction of data from victim Oracle databases with SQLULDR2, export of Oracle data to local CSV files, compression with RAR, and exfiltration to OneDrive. The cluster also deleted artifacts after use and conducted target development using internet scan data, search engines, and access to external victim websites.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
"Akira will exfiltrate victim data using applications such as Rclone"; "APT41 DUST exfiltrated collected information to OneDrive"; "...upload data...in Dropbox"; "...exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command..."; "...exfiltrated data to Google Drive"; "...use an attacker-controlled OneDrive account for exfiltration"; "...via the Microsoft Graph API"; "Turla has also exfiltrated stolen files to OneDrive and 4shared"
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses HTTPS for command-and-control communications.
APT41 malware/tooling cluster referenced as 'DUST' that uses HTTPS and cloud-based infrastructure (e.g., Cloudflare Workers, compromised Google Workspace accounts) for command-and-control, stages and exfiltrates data (e.g., Oracle DB exports) and uses web shells and signed components in the intrusion chain.
Malware used with HTTPS-based command and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.