DustySky is a malware campaign associated by multiple researchers with the Gaza Cybergang and focused on government interests in the Middle East. The activity has used politically themed Arabic- and Hebrew-language decoy documents and operational timing consistent with the regional work week, indicating a regional targeting focus. Observed intrusion chains likely began via email or web-delivered droppers that installed the Downeks downloader, which then fetched a customized Quasar RAT payload. The campaign’s tooling includes both native and .NET variants of Downeks, including a .NET variant internally named SharpDownloader. Downeks functions primarily as a downloader and lightweight backdoor, with capabilities including command polling, download-and-execute, execution of existing binaries, self-update, screen capture, external IP discovery for likely victim filtering, antivirus enumeration, and persistence through startup mechanisms. DustySky operators also used a modified fork of the open-source Quasar RAT with packing, obfuscation, altered serialization, and customized cryptography. The Quasar payload supported extensive post-compromise functionality including system reconnaissance, file management, process control, registry editing, reverse proxying, remote desktop, desktop observation, remote input control, password theft, and keylogging. Attribution to DustySky has been supported through overlaps in infrastructure, malware characteristics, metadata, mutex patterns, fake program metadata, and shared operational behavior. The campaign is commonly discussed in connection with the Gaza Cybergang, a threat cluster known for targeting regional government entities. DustySky should be understood as an espionage-oriented intrusion set centered on politically relevant targets rather than a ransomware or financially motivated operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
143 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an attack group that used Quasar 1.1.0.0 without customization in the comparison table.
A campaign linked to attacks using the Downeks downloader and modified Quasar RAT, with Arabic and Hebrew political decoys and targeting government interests in the Middle East.
A campaign linked to attacks using the Downeks downloader and modified Quasar RAT, targeting government interests in the Middle East and using Arabic and Hebrew political decoy documents.
A campaign linked to attacks in the Middle East using the Downeks downloader and modified Quasar RAT, with decoy political documents in Arabic or Hebrew and targeting government interests in the region.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.