logo

APT41 Has Arisen From the DUST

ID: eec28d97-c395-50d8-9d33-cf976601cd7a

STIX ID: report--eec28d97-c395-50d8-9d33-cf976601cd7a

Feed Name: Google Cloud Threat Intelligence

Threat Score
88/100

Date Published: 2024-07-18

Date Updated: 2026-04-27

Author: Mandiant

...
...

This report describes APT41-associated modular malware: DUSTPAN is an in-memory dropper that decrypts and executes embedded or disk-loaded payloads (often BEACON) and persists via Windows services, while DUSTTRAP is a multi-stage plugin framework that uses MachineGUID-keyed AES decryption, trojanizes legitimate DLLs to load plugins in memory, and employs evasion to avoid EDR detection; BEACON payloads use Cloudflare-based C2 channels. The document provides technical TTPs and IOCs intended for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.