DUSTMAN

First seen
2019-12-29 00:00:00
Malware type
wiper
Profile updated
2026-07-07 12:39:05

Targeted industries: energy-and-utilities

Targeted regions: country_code:sa country_code:ae

Context

In 2019, multiple destructive attacks were observed targeting entities within the Middle East. The National Cyber Security Centre (NCSC), a part of the National Cybersecurity Authority (NCA), detected a new malware named "DUSTMAN" that was detonated on December 29, 2019. Based on analyzed evidence and artifacts found on machines in a victim’s network that were not wiped by the malware. NCSC assess that the threat actor behind the attack had some kind of urgency on executing the files on the date of the attack due to multiple OPSEC failures observed on the infected network. NCSC is calling the malware used in this attack "DUSTMAN" after the filename and string embedded in the malware. "DUSTMAN" can be considered as a new variant of "ZeroCleare" malware, published in December 2019.

Detection coverage

  • 2 YARA rules

Detection rules

  • ARKBIRD_SOLG_APT_APT34_Dustman_Apr_2021_1 (yara-rule)
  • MALPEDIA_Win_Dustman_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • CrowdStrike — The Anatomy Of Wiper Malware Part 1 (report)
  • CrowdStrike — The Anatomy Of Wiper Malware Part 3 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Dustman (report)
  • scribd.com — Saudi Arabia Cna Report (report)
  • twitter.com — 1213544175355908096 (report)
  • swapcontext.blogspot.com — Dustman Apt Art Of Copy Paste (report)
  • linkedin.com — Iasrar Dustman Report In English Activity 6619216346083393537 Nv1Z (report)

External references