DUSTPAN is a Windows in-memory dropper associated with APT41, also tracked in some reporting as part of the group's DUST tooling cluster. Implemented in C/C++, it is designed to decrypt and execute embedded payloads directly in memory. Some variants can also retrieve an external payload from disk using a hard-coded encrypted path stored in the PE file. Observed execution paths include running the decrypted payload in the current process via a new thread or injecting it into another process. In documented intrusions, DUSTPAN has been used to load BEACON payloads encrypted with ChaCha20, enabling follow-on command-and-control and post-compromise activity.
DUSTPAN has been used in espionage-oriented operations attributed to APT41, including activity in 2021, 2022, and later resurfacing in subsequent investigations. Operators have disguised the malware as legitimate Windows binaries and established persistence through Windows services, including service names crafted to resemble benign system components. It has also been executed after download through web-shell-enabled intrusion chains. The malware's role is primarily as a memory-resident staging component that decrypts and launches secondary payloads while minimizing on-disk exposure, supporting stealthy post-exploitation operations in enterprise Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE ATLAS ... Tools ... Acehash, CCleaner v5.33 backdoor, ChinaChopper, Cobalt Strike, Dicey MSDN, Dodgebox, DUSTPAN, ForkPlayground, HUC Proxy Malware (Htran)
APT41 DUST used Windows Services with names such as Windows Defend for persistence of DUSTPAN. DUSTPAN can persist as a Windows Service in operations.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
APT41 disguised DUSTPAN as a Windows binary by executing the malicious file as w3wp.exe or conn.exe.
Akira has used legitimate names and locations for files to evade defenses.
DUSTPAN may be configured to inject the decrypted payload into another process or create a new thread and execute it within its own process space.
DUSTPAN is an in-memory dropper written in C/C++ that decrypts and executes an embedded payload.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an APT41-associated tool similar to Amaranth Loader.
Referenced as an APT41-associated tool similar to Amaranth Loader; specific functionality not described in the provided content.
Listed as a tool used by the BRONZE ATLAS threat profile.
DUSTPAN is a backdoor used by APT41 for command and control and persistent access in targeted cyberespionage operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.