Skip to main content
QUIETLYTIC
Campaign

APT41 DUST

APT41's use of DUSTPAN and the newly observed DUSTTRAP malware, alongside Cobalt Strike and certutil, against shipping, logistics, and media entities in Europe, Asia, and the Middle East from 2023 to mid-2024.

Threat Level
HIGH
Status
Resolved
Actors Involved
APT41
Targets
Shipping, logistics, and media sectors, Europe, Asia, and the Middle East

Overview

APT41 DUST (MITRE ATT&CK ID C0040) was conducted by APT41 from 2023 to mid-2024 against entities in Europe, Asia, and the Middle East, per MITRE’s campaign profile. MITRE documents the campaign as targeting the shipping, logistics, and media sectors for information-gathering purposes. APT41 used previously observed malware, including DUSTPAN, alongside a newly observed tool documented for the first time in this campaign, DUSTTRAP.

Timeline

Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from early 2023 to mid-2024.

Actors and malware involved (per MITRE ATT&CK relationship data)

MITRE ATT&CK attributes this campaign to APT41. Malware and tools documented in this campaign include DUSTPAN, the newly observed DUSTTRAP, Cobalt Strike, and the legitimate Windows utility certutil — a mix of custom-built and living-off-the-land tooling consistent with APT41’s broader documented pattern of combining bespoke malware with abuse of legitimate system tools. See our Cobalt Strike profile for what that specific tool does.

What we don’t have

MITRE’s ingested data doesn’t specify the exact initial-access method used against individual victim organizations in this campaign, and the campaign’s stated goals beyond information gathering are not detailed further in MITRE’s own description. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.

Frequently Asked Questions

What was APT41 DUST? A campaign, per MITRE ATT&CK, in which APT41 targeted shipping, logistics, and media organizations across Europe, Asia, and the Middle East from 2023 to mid-2024, using both previously known malware and a newly documented tool, DUSTTRAP.

Who was behind APT41 DUST? APT41, per MITRE ATT&CK’s relationship data.

Is APT41 DUST related to Operation CuckooBees? Both are documented as APT41-linked activity, but they’re separate MITRE ATT&CK campaign entries with different timeframes and targeting — see our Operation CuckooBees profile for that earlier campaign.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0040, aggregated September 20, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Cross-referenced intelligence


Analyst tools