high_confidence

APT41 DUST

[APT41 DUST](https://attack.mitre.org/campaigns/C0040) was conducted by [APT41](https://attack.mitre.org/groups/G0096) from 2023 to July 2024 against entities in Europe, Asia, and the Middle East. [APT41 DUST](https://attack.mitre.org/campaigns/C0040) targeted sectors such as shipping, logistics, and media for information gathering purposes. [APT41](https://attack.mitre.org/groups/G0096) used previously-observed malware such as [DUSTPAN](https://attack.mitre.org/software/S1158) as well as newly observed tools such as [DUSTTRAP](https://attack.mitre.org/software/S1159) in [APT41 DUST](https://attack.mitre.org/campaigns/C0040).(Citation: Google Cloud APT41 2024)

Start date
31 January 2023
End date
30 June 2024
Techniques
23

Attributed actors

Techniques (23)

collection4
T1119Automated Collection
T1213.006Databases
T1074.001Local Data Staging
T1560.001Archive via Utility
command-and-control4
T1102Web Service
T1573.002Asymmetric Cryptography
T1105Ingress Tool Transfer
T1071.001Web Protocols
defense-impairment1
T1553.002Code Signing
execution2
T1569.002Service Execution
T1574.001DLL
exfiltration1
T1567.002Exfiltration to Cloud Storage
persistence2
T1505.003Web Shell
T1543.003Windows Service
privilege-escalation1
T1543.003Windows Service
reconnaissance3
T1596.005Scan Databases
T1594Search Victim-Owned Websites
T1593.002Search Engines
resource-development3
T1583.007Serverless
T1586.003Cloud Accounts
T1588.003Code Signing Certificates
stealth4
T1036.004Masquerade Task or Service
T1070.004File Deletion
T1574.001DLL
T1027.013Encrypted/Encoded File

Indicators of compromise

No IOCs linked to this campaign yet.