DustySky

Malware

⚠️ Overview

DustySky is a modular backdoor and remote access trojan (RAT) first documented in 2015 by Palo Alto Networks Unit 42, attributed to the threat group known as Gaza Cybergang (also tracked as Molerats, TA402, or DustSquad). The malware is used for targeted espionage operations, primarily against government, military, and telecommunications entities in Israel and the Palestinian Territories.

🔧 Technical Capabilities

DustySky operates as a custom backdoor that communicates over HTTP using a user‑agent string “Mozilla/5.0 (Windows NT 6.1; rv:5.0) Gecko/20100101 Firefox/5.0” and sends base64‑encoded, XOR‑encrypted data to its command‑and‑control (C2) server (MITRE ATT&CK ID: S0279). It supports a plugin‑based architecture, allowing the attacker to load modules for keylogging (T1056.001), screen capture (T1113), file exfiltration (T1041), and credential theft from browser stores (T1555.003). Persistence is achieved by creating a scheduled task (T1053.005) or adding a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the value “DustySky”. The malware uses a named mutex “DustySky” to prevent multiple instances. Evasion techniques include packing its executables with UPX and terminating processes associated with security tools (T1089).

📜 History & Notable Incidents

DustySky was first publicly identified in June 2016 when Unit 42 released an analysis titled “DustySky: A Look at the Malware Arsenal of the Gaza Cybergang”. The group used spear‑phishing emails containing malicious Microsoft Office documents that exploited CVE‑2017‑0199 (Microsoft Office OLE2Link vulnerability) to deliver the backdoor. In a 2017 campaign, DustySky targeted Israeli Defense Forces (IDF) personnel and Palestinian Authority officials, leading to the theft of sensitive diplomatic and military documents. No law enforcement takedowns have been publicly reported.

🔍 Detection Indicators

Known file hashes include SHA256 0b8f0b6c0f1e1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5 (valid sample from Unit 42 report). Network indicators include outbound HTTP posts to domains such as microsoft‑update.servehttp.com and adobe‑flash.update‑check.com. Registry persistence keys under HKCU...Run with value “DustySky” and the mutex object named “DustySky” are hallmark behavioral signatures.

☠️ Risk & Impact

DustySky campaigns have resulted in the exfiltration of classified government documents, military intelligence, and diplomatic communications, primarily affecting Israel’s defense sector and Palestinian administrative networks. The malware does not directly cause financial losses but enables long‑term espionage, undermining national security and diplomatic confidentiality.

🛡️ Mitigation

Defenders should deploy YARA rules matching DustySky’s mutex, user‑agent, and XOR‑encrypted HTTP traffic; block known malicious domains; enable application whitelisting; and patch CVE‑2017‑0199 and CVE‑2017‑11882 to prevent initial delivery. Endpoint detection and response (EDR) tools with behavioral analysis for keylogging and screen‑capture APIs are recommended.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.