Overview
APT41 DUST (MITRE ATT&CK ID C0040) was conducted by APT41 from 2023 to mid-2024 against entities in Europe, Asia, and the Middle East, per MITRE’s campaign profile. MITRE documents the campaign as targeting the shipping, logistics, and media sectors for information-gathering purposes. APT41 used previously observed malware, including DUSTPAN, alongside a newly observed tool documented for the first time in this campaign, DUSTTRAP.
Timeline
Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from early 2023 to mid-2024.
Actors and malware involved (per MITRE ATT&CK relationship data)
MITRE ATT&CK attributes this campaign to APT41. Malware and tools documented in this campaign include DUSTPAN, the newly observed DUSTTRAP, Cobalt Strike, and the legitimate Windows utility certutil — a mix of custom-built and living-off-the-land tooling consistent with APT41’s broader documented pattern of combining bespoke malware with abuse of legitimate system tools. See our Cobalt Strike profile for what that specific tool does.
What we don’t have
MITRE’s ingested data doesn’t specify the exact initial-access method used against individual victim organizations in this campaign, and the campaign’s stated goals beyond information gathering are not detailed further in MITRE’s own description. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.
Frequently Asked Questions
What was APT41 DUST? A campaign, per MITRE ATT&CK, in which APT41 targeted shipping, logistics, and media organizations across Europe, Asia, and the Middle East from 2023 to mid-2024, using both previously known malware and a newly documented tool, DUSTTRAP.
Who was behind APT41 DUST? APT41, per MITRE ATT&CK’s relationship data.
Is APT41 DUST related to Operation CuckooBees? Both are documented as APT41-linked activity, but they’re separate MITRE ATT&CK campaign entries with different timeframes and targeting — see our Operation CuckooBees profile for that earlier campaign.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0040, aggregated September 20, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.