logo

Operation Dust Storm

ID: cadd1e3b-8bfc-4fe4-ae25-f6b19232de17

STIX ID: report--cadd1e3b-8bfc-4fe4-ae25-f6b19232de17

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2016-02-22

Last Modified Date: 2016-02-22

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation Dust Storm is a multi-year APT campaign documented by Cylance SPEAR that has conducted targeted espionage since ~2010 against government, defense, and later Japanese critical infrastructure sectors (power, oil & gas, finance, transportation, construction). The report provides chronology, exploitation of multiple zero-days (e.g., CVE-2011-0611, CVE-2011-1255, CVE-2014-0322), delivery methods (spearphishing, watering holes, malicious attachments, Dynamic DNS), deep implant analyses (Misdat, hybrid, S-Type, Zlib, and Android malware), and a large set of IoCs (file hashes, domains, IP addresses) to support detection and response.