DUSTPAN — Malware Profile
DUSTPAN is an in-memory dropper written in C/C++ used by APT41 since 2021 that decrypts and executes an embedded payload.
MITRE ATT&CK techniques (6)
- T1027.009 Embedded Payloads
- T1027.013 Encrypted/Encoded File
- T1036.005 Match Legitimate Resource Name or Location
- T1055.002 Portable Executable Injection
- T1140 Deobfuscate/Decode Files or Information
- T1543.003 Windows Service