SQLULDR2 is an Oracle database extraction utility used to export data from Oracle databases. It has been used by the China-nexus APT41 DUST activity cluster during cyber-espionage operations to collect database information from compromised environments. In observed operations, database exports were staged as CSV files, compressed, and transferred alongside other collected data for exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Oracle database dumping/extraction utility used to collect/export data from victim Oracle databases (e.g., to local CSV) prior to staging/exfiltration.
Tool used to gather database information (notably from Oracle environments) as part of collection activities.
A database extraction utility used by APT41 to extract data from Oracle databases on compromised environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.