Campaign · all campaigns
APT41 DUSTC0040 state-contractor
🇨🇳 CN · MSS
aka APT41 DUST
Run by APT41
Last updated: 2026-08-20
About this actor
[APT41 DUST](https://attack.mitre.org/campaigns/C0040) was conducted by [APT41](https://attack.mitre.org/groups/G0096) from 2023 to July 2024 against entities in Europe, Asia, and the Middle East. [APT41 DUST](https://attack.mitre.org/campaigns/C0040) targeted sectors such as shipping, logistics, and media for information gathering purposes. [APT41](https://attack.mitre.org/groups/G0096) used previously-observed malware such as [DUSTPAN](https://attack.mitre.org/software/S1158) as well as newly observed tools such as [DUSTTRAP](https://attack.mitre.org/software/S1159) in [APT41 DUST](https://attack.mitre.org/campaigns/C0040).(Citation: Google Cloud APT41 2024)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
Microsoftweather-system names
How we know this
- Data origin
- MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
- Techniques
- MITRE ATT&CK STIX mappings — 42 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1027Obfuscated Files or Information ↗T1027.013Encrypted/Encoded File ↗T1036Masquerading ↗T1036.004Masquerade Task or Service ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1102Web Service ↗T1105Ingress Tool Transfer ↗T1119Automated Collection ↗T1213Data from Information Repositories ↗T1213.006Databases ↗T1505Server Software Component ↗T1505.003Web Shell ↗T1543Create or Modify System Process ↗T1543.003Windows Service ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1567Exfiltration Over Web Service ↗T1567.002Exfiltration to Cloud Storage ↗T1569System Services ↗T1569.002Service Execution ↗T1573Encrypted Channel ↗T1573.002Asymmetric Cryptography ↗T1574Hijack Execution Flow ↗T1574.001DLL ↗T1583Acquire Infrastructure ↗T1583.007Serverless ↗T1586Compromise Accounts ↗T1586.003Cloud Accounts ↗T1588Obtain Capabilities ↗T1588.003Code Signing Certificates ↗T1593Search Open Websites/Domains ↗T1593.002Search Engines ↗T1594Search Victim-Owned Websites ↗T1596Search Open Technical Databases ↗T1596.005Scan Databases ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
CM-2 | 22 / 42 | 52% |
SI-4 | 22 / 42 | 52% |
CM-6 | 19 / 42 | 45% |
SI-3 | 18 / 42 | 43% |
CM-7 | 15 / 42 | 36% |
CA-7 | 14 / 42 | 33% |
AC-3 | 13 / 42 | 31% |
AC-2 | 12 / 42 | 29% |
AC-6 | 12 / 42 | 29% |
SI-7 | 12 / 42 | 29% |
AC-4 | 10 / 42 | 24% |
SC-7 | 10 / 42 | 24% |
AC-5 | 9 / 42 | 21% |
CM-5 | 8 / 42 | 19% |
RA-5 | 8 / 42 | 19% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Operation Honeybee 0.31
- C0017 0.22
- FIN6 0.22
- Threat Group-3390 0.21
- BackdoorDiplomacy 0.21
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- C0017 1.00
- RedDelta Modified PlugX Infection Chain Operations 1.00
- APT3 1.00
- APT41 1.00
- Mustang Panda 1.00