SQLULDR2 is a tool used by the APT41 DUST cluster to gather local system and database information and to collect data from victim Oracle databases. In the described activity, APT41 DUST used SQLULDR2 as part of a broader intrusion focused on Oracle database theft: data was collected from Oracle databases using SQLULDR2, exported to local CSV files, compressed with RAR, and then exfiltrated to OneDrive. The reporting directly associates SQLULDR2 with automated collection from compromised environments and specifically with Oracle database data extraction. It is mentioned alongside PINEGROVE as part of APT41 DUST tooling. High-confidence context ties its use to APT41 DUST operations that also employed HTTPS-based command and control, Cloudflare infrastructure or Cloudflare Workers, compromised Google Workspace accounts, web shells such as ANTSWORD and BLUEBEAM, and malware including DUSTPAN and DUSTTRAP. The content does not provide standalone technical details such as platform support, persistence, or specific file indicators for SQLULDR2 itself beyond its role in gathering local system and Oracle database information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information.
1 distinct technique documented for this family, organized by ATT&CK tactic.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Oracle database dumping/extraction utility used to collect/export data from victim Oracle databases (e.g., to local CSV) prior to staging/exfiltration.
Tool used to gather database information (notably from Oracle environments) as part of collection activities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.