Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware DustySky

DustySky

TLP:CLEAR
Family

Also known as: NeD Worm

AI Analysis

· 1 day ago

Executive Summary

DustySky delivers a sophisticated, multi‑stage .NET‑based RAT used by the Iranian Molerats group. It persistently harvests credentials, logs keystrokes, captures screenshots, and exfiltrates data while remaining hidden through obfuscation, DLL injection, and lateral movement via RDP and SMB.

Enhanced Description

DustySky is a multi‑stage, .NET‑based remote access trojan that has been deployed by the Iranian threat group known as Molerats since at least May 2015. The malware operates in several phases: an initial loader establishes persistence on the victim host—often via Registry run keys or scheduled tasks—before spawning additional lightweight components. These secondary modules are responsible for credential harvesting, keylogging, screenshot capture, and exfiltration of stolen data through either SMTP channels or HTTP/HTTPS‑based C&C servers. DustySky exhibits sophisticated obfuscation and packing techniques that enable it to evade signature‑based defenses. Its developers have incorporated DLL injection against legitimate Windows processes, allowing the malware to run in trusted contexts and evade host‑based detections. The modular design also permits lateral movement over RDP, SMB, or other administrative shares, which aligns with common Molerats tactics. In addition to standard RAT functionality, DustySky can disable security services (e.g., Windows Defender), erase system logs, and maintain persistence across reboots by injecting binaries into legitimate Microsoft binaries. The combination of .NET stealth, robust exfiltration, and lateral movement capability makes it a persistent threat in environments where user privilege escalation or inadequate segmentation is accepted.

Key Capabilities

  • Multi‑stage .NET architecture
  • Registry and scheduled task persistence
  • Keylogging and screenshot capture
  • Credential harvesting and basic dumping
  • DLL injection into legitimate processes
  • Exfiltration via SMTP or HTTPS channels
  • Disables security services and evades logs
  • Lateral movement over RDP/SMB

Recommended Actions

  • Deploy behavior‑based endpoint protection to detect keylogging, screen‑capture, and DLL injection activity.
  • Implement application whitelisting with strict allowlists for .NET binaries. Use EDR that surfaces persistence via registry or scheduled task creation. Block outbound connections to known DustySky C&C IP ranges using a next‑generation firewall. Apply MFA and restrict RDP access; enforce least privilege on administrative shares. Patch Windows and the .NET Framework promptly to reduce exploitation vectors.

Description

DustySky is multi-stage malware written in .NET that has been used by Molerats since May 2015. (Citation: DustySky) (Citation: DustySky2)(Citation: Kaspersky MoleRATs April 2019)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.