Cyber Resilience

Campaign · all campaigns

APT41 DUSTC0040 state-contractor

🇨🇳 CN · MSS

aka APT41 DUST

Run by APT41

Last updated: 2026-08-20

0attributed CVEs
42ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

[APT41 DUST](https://attack.mitre.org/campaigns/C0040) was conducted by [APT41](https://attack.mitre.org/groups/G0096) from 2023 to July 2024 against entities in Europe, Asia, and the Middle East. [APT41 DUST](https://attack.mitre.org/campaigns/C0040) targeted sectors such as shipping, logistics, and media for information gathering purposes. [APT41](https://attack.mitre.org/groups/G0096) used previously-observed malware such as [DUSTPAN](https://attack.mitre.org/software/S1158) as well as newly observed tools such as [DUSTTRAP](https://attack.mitre.org/software/S1159) in [APT41 DUST](https://attack.mitre.org/campaigns/C0040).(Citation: Google Cloud APT41 2024)

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

Microsoftweather-system names

APT41 DUST

How we know this

Data origin
MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
Techniques
MITRE ATT&CK STIX mappings — 42 ATT&CK techniques on file.
Named victims
None on file.

See how actor data is built for the full pipeline.

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
CM-222 / 4252%
SI-422 / 4252%
CM-619 / 4245%
SI-318 / 4243%
CM-715 / 4236%
CA-714 / 4233%
AC-313 / 4231%
AC-212 / 4229%
AC-612 / 4229%
SI-712 / 4229%
AC-410 / 4224%
SC-710 / 4224%
AC-59 / 4221%
CM-58 / 4219%
RA-58 / 4219%

Co-occurring actors

None.

Similar actors

Same nation-state