APT41 Has Arisen From the DUST | Google Cloud Blog
ID: 13da0e33-186f-4dd0-8ddf-51c33e94c164
STIX ID: report--13da0e33-186f-4dd0-8ddf-51c33e94c164
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2024-07-25
Last Modified Date: 2024-07-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** Mandiant (with Google TAG) attributes a sustained 2023–2024 intrusion campaign to APT41 targeting shipping/logistics, media, technology and automotive organizations across multiple countries; attackers used ANTSWORD/BLUEBEAM web shells to deploy DUSTPAN (to load BEACON) and the multi-stage DUSTTRAP plugin framework for persistence, lateral movement and data theft, leveraging SQLULDR2 and PINEGROVE to extract and exfiltrate Oracle database data (to OneDrive), and abused stolen code-signing certificates — the report provides technical analysis, IOCs and YARA rules for detection and hunting.
