DustySky
DustySky, also called “NeD Worm” by its developer, is a multi-stage Windows malware family reported in use since May 2015. It has been used by the Molerats threat group. Documented capabilities include host reconnaissance and collection, such as using Windows Management Instrumentation (WMI) to extract operating system information and determine whether antivirus is active, checking for the existence of antivirus, listing installed software, and detecting connected USB devices. DustySky also contains a keylogger and captures PNG screenshots of the main screen. For collection and exfiltration, it creates folders in temporary directories to stage collected files, can compress staged data with RAR, and has exfiltrated data to its command-and-control server. It can delete files it creates from the infected system after use. High-confidence behaviors directly mentioned in the source include temporary-directory staging, RAR archiving prior to exfiltration, screenshot capture, keylogging, USB device detection, installed-software enumeration, antivirus checks, WMI-based system discovery, exfiltration to C2, and cleanup via file deletion.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DustySky (called “NeD Worm” by its developer) is a multi-stage malware in use since May 2015.
Techniques & procedures
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
6 techniquesIn one case, the attackers used stolen email credentials and logged in from 96.44.156.201, potentially their proxy or VPN endpoint.
DustySky Core is a Trojan backdoor... Searching for removable media and network drives, and duplicating itself into them.
IP address 45.32.13.169 and all the domains that are pointing to it host a webpage which is a copy of a legitimate and unrelated software website - iMazing... the version on the fake website is bundled with DustySky malware.
If the target is using Windows, DuskySky is served. If the operating system is different than Windows, the target is served a Google, Microsoft, or Yahoo phishing page.
The attackers would usually send a malicious email message that either links to an archive file (RAR or ZIP compressed) or has one attached to it.
The attackers would usually send a malicious email message that either links to an archive file (RAR or ZIP compressed) or has one attached to it.
Execution
2 techniquesThe dropper uses Windows Management Instrumentation to extract information about the operating system and whether an antivirus is active.
If the victim extracts the archive and clicks the .exe file, the lure document or video are presented while the computer is being infected with DustySky. | In recent samples the group used Microsoft Word files embed with a malicious macro, which would infect the victim if enabled. Note, that these infection methods rely on social engineering - convincing the victim to open the file (and enabling content if it is disabled) - and not on software vulnerabilities.
Persistence
2 techniquesPrivilege Escalation
2 techniquesStealth
4 techniquesThe dropper uses the following function to obfuscate the name of functions and other parts of the malware (In later versions, SmartAssembly 6.9.0.114 .NET obfuscator was used).
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
Credential Access
2 techniquesOne of the components contained in DustySky core is a keylogger... When ordered by the command and control server, the keylogger is extracted and executed. Keylogging logs are saved to %TEMP%\temps.
They used BrowserPasswordDump, a public and free-to-use tool that recovers passwords saved in browsers.
Discovery
7 techniquesThe dropper uses Windows Management Instrumentation to extract information about the operating system and whether an antivirus is active.
They took screenshots and a list of active processes in the computer, and sent them to their command and control severs.
The DustySky dropper tries to evade running in a virtual machine. Once sure the computer is not a VM, it extracts, runs and adds persistency to DustySky Core. It extracts basic information about the operating system and checks for the existence of an Antivirus.
The malware would also scan the computer for files that contain certain keywords. The list of keywords, in base64 format, is retrieved from the command and control as a text file.
The content repeatedly describes malware and threat actors identifying, monitoring, or enumerating connected peripheral devices such as USB mass storage, Bluetooth devices, printers, smart card readers, cameras, Apple devices, VGA/display devices, and removable drives.
For VM evasion the dropper checks whether there is a DLL that indicate that the malware is running in a virtual machine... If the dropper is indeed running in a virtual machine, it will open the lure document and stop its activity.
DustySky Core is a Trojan backdoor and the main component of the malware. It has the following capabilities: Collecting information about the OS version, running processes and installed software.
Lateral Movement
1 techniqueCollection
4 techniquesOne of the components contained in DustySky core is a keylogger... When ordered by the command and control server, the keylogger is extracted and executed. Keylogging logs are saved to %TEMP%\temps.
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
They took screenshots and a list of active processes in the computer, and sent them to their command and control severs.
Multiple actors and tools are described as using 7-Zip/WinRAR/zip/tar/gzip/makecab/PowerShell Compress-Archive to compress (often password-protect/encrypt) collected data prior to exfiltration (e.g., “used 7zip to archive extracted data in preparation for exfiltration”, “created password-protected RAR archives prior to exfiltration”, “used built-in PowerShell capabilities (Compress-Archive cmdlet) to compress collected data”).
Command and Control
4 techniquesDustySky has two hardcoded domains of command and control servers. It starts by checking if the first one is alive by sending a GET request to TEST.php or index.php, expecting “OK” as response.
Recently, command and control communication changed from HTTP to HTTPS.
After infecting the computer, the attackers used both the capabilities of DustySky, and those of public hacking tools they had subsequently downloaded to the computer.
DustySky Core is a Trojan backdoor and the main component of the malware... receives and executes commands.
Exfiltration
1 techniqueDustySky Core is a Trojan backdoor... It communicates with the command and control server, exfiltrates collected data, information and files, and receives and executes commands.
IOCs tracked for this family
227 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
Recent activity
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used by Molerats to stage and archive collected files prior to exfiltration.
Backdoor malware capable of detecting connected USB devices.
Dropper that uses WMI to identify OS details and active antivirus protections.
Backdoor that exfiltrates data to its C2 server.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.