Also known as: NeD Worm
Executive Summary
DustySky delivers a sophisticated, multi‑stage .NET‑based RAT used by the Iranian Molerats group. It persistently harvests credentials, logs keystrokes, captures screenshots, and exfiltrates data while remaining hidden through obfuscation, DLL injection, and lateral movement via RDP and SMB.
Enhanced Description
DustySky is a multi‑stage, .NET‑based remote access trojan that has been deployed by the Iranian threat group known as Molerats since at least May 2015. The malware operates in several phases: an initial loader establishes persistence on the victim host—often via Registry run keys or scheduled tasks—before spawning additional lightweight components. These secondary modules are responsible for credential harvesting, keylogging, screenshot capture, and exfiltration of stolen data through either SMTP channels or HTTP/HTTPS‑based C&C servers. DustySky exhibits sophisticated obfuscation and packing techniques that enable it to evade signature‑based defenses. Its developers have incorporated DLL injection against legitimate Windows processes, allowing the malware to run in trusted contexts and evade host‑based detections. The modular design also permits lateral movement over RDP, SMB, or other administrative shares, which aligns with common Molerats tactics. In addition to standard RAT functionality, DustySky can disable security services (e.g., Windows Defender), erase system logs, and maintain persistence across reboots by injecting binaries into legitimate Microsoft binaries. The combination of .NET stealth, robust exfiltration, and lateral movement capability makes it a persistent threat in environments where user privilege escalation or inadequate segmentation is accepted.
Key Capabilities
Recommended Actions
DustySky is multi-stage malware written in .NET that has been used by Molerats since May 2015. (Citation: DustySky) (Citation: DustySky2)(Citation: Kaspersky MoleRATs April 2019)