Skip to content

Malware

DUSTMAN

In 2019, multiple destructive attacks were observed targeting entities within the Middle East.

DUSTMAN is a Windows malware family.

Background

During 2019, several destructive operations were seen striking organizations across the Middle East. The National Cyber Security Centre (NCSC), part of the National Cybersecurity Authority (NCA), identified a new piece of malware called "DUSTMAN" that was triggered on December 29, 2019. Drawing on evidence and artifacts recovered from machines in a victim network that the malware had not wiped, the NCSC concluded that the threat actor acted with some urgency to run the files on the attack date, given the numerous OPSEC mistakes left across the compromised network. The NCSC named the malware "DUSTMAN" based on a filename and a string embedded within it, and regards it as a new variant of the "ZeroCleare" wiper that was disclosed in December 2019.


Source: Malpedia (Fraunhofer FKIE).