Threats Feed|Unclassified|Last Updated 08/07/2026|AuthorCertfa Radar|Publish Date17/01/2020

Unveiling Dustman: A ZeroCleare Offshoot Wiping Data in the Middle East

  • Actor Motivations: Sabotage
  • Attack Vectors: Vulnerability Exploitation,Dropper,Wiper
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The IBM X-Force IRIS report details the emergence of Dustman, a malware variant in the Wiper class, related to the previously identified ZeroCleare. Discovered in attacks in the Middle East, Dustman is primarily used for destructive purposes, targeting regional organizations. It shares similarities with ZeroCleare in components, including the use of the Turla driver and an EldoS RawDisk driver for disk wiping. However, Dustman shows differences in deployment flow and file names. The malware consists of a binary file, Dustman.exe, which loads the EldoS RawDisk driver, and an agent.exe binary identified as the wiper. Despite these similarities, Dustman features a modified execution order and distinct political messaging, targeting both fixed and removable drives.

Detected Targets

TypeDescriptionConfidence
SectorOil and Gas
Verified
RegionSaudi Arabia
Verified
RegionMiddle East Countries
Verified

Extracted IOCs

  • 1a69a02b0cd10b1764521fec4b7376c9
  • 1ef610b1f9646063f96ad880aad9569d
  • 8afa8a59eebf43ef223be52e08fcdc67
  • 993e9cb95301126debdea7dd66b9e121
  • eaea9ccb40c82af8f3867cd0f4dd5e9d
  • f5f8160fe8468a77b6a495155c3dacea
  • 20d61c337653392ea472352931820dc60c37b2bc
  • 7c1b25518dee1e30b5a6eaa1ea8e4a3780c24d0c
  • a7133c316c534d1331c801bbcd3f4c62141013a1
  • 36a4e35abf2217887e97041e3e0b17483aa4d2c1aee6feadd48ef448bf1b9e6c
  • 44100c73c6e2529c591a10cd3668691d92dc0241152ec82a72c6e63da299d3a2
  • cf3a7d4285d65bf8688215407bce1b51d7c6b22497f09021f0fce31cbeb78986
download

Tip: 12 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 12 file hash) to this threat have been found.

Overlaps

UnclassifiedThe Rise of Dustman: Data-Wiping Cyberattacks Traced to Iran

Source: The Vault - January 2020

Detection (three cases): 20d61c337653392ea472352931820dc60c37b2bc, 7c1b25518dee1e30b5a6eaa1ea8e4a3780c24d0c, a7133c316c534d1331c801bbcd3f4c62141013a1

ITG13ZeroCleare Wiper Targets Middle Eastern Energy Sector in Destructive Cyberattack

Source: IBM - December 2019

Detection (six cases): 1a69a02b0cd10b1764521fec4b7376c9, 1ef610b1f9646063f96ad880aad9569d, 36a4e35abf2217887e97041e3e0b17483aa4d2c1aee6feadd48ef448bf1b9e6c, 993e9cb95301126debdea7dd66b9e121, cf3a7d4285d65bf8688215407bce1b51d7c6b22497f09021f0fce31cbeb78986, eaea9ccb40c82af8f3867cd0f4dd5e9d

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

The Dustman Wiper Attacks

A new piece of destructive computer software known as "Dustman" was deployed in cyberattacks in the Middle East. Security researchers discovered that it is a slightly modified copycat of an earlier destructive virus named "ZeroCleare," which had recently been reported in the same region.

The report does not definitively name the specific individuals or group behind the attacks. However, researchers noted that the perpetrators relied heavily on shared code and tools from previous attacks, even though their specific methods for breaking into networks differed from the original ZeroCleare campaign.

The primary goal of this attack is purely destructive. The software is specifically designed to completely wipe the data from infected hard drives, making the computers completely unusable, while leaving behind a political message.

The attacks were specifically focused on entities located in the Middle East region. Once the virus infects a computer, it is capable of identifying and destroying data on both the computer's permanent hard drives and any removable drives plugged into it.

While the exact industries are not explicitly listed, the targets were clearly tied to Saudi Arabian interests. The virus intentionally overwrites the destroyed computer files with the message "Down With Saudi Kingdom, Down With Bin Salman," indicating politically motivated targeting.

The attackers used a primary malicious file that exploited a vulnerability in a legitimate software driver to sneak past Windows security defenses. Once the computer's security was bypassed, the main file released a secondary wiping tool that systematically erased all connected hard drives.

Given the highly specific political messages embedded in the software, these entities were attractive targets because attacking them allowed the threat actors to make a hostile political statement against the Saudi kingdom. The attacks were designed to cause maximum disruption to regional interests.

Organizations should monitor their computer networks for the specific vulnerable software drivers and files the attackers used to bypass security. Security teams can use the unique file names, system markers, and operational patterns outlined in the threat report to block this software from running.

This is a highly targeted issue rather than a widespread global threat. The attacks were geographically focused on the Middle East and utilized highly tailored political messaging, indicating the attackers had a specific regional agenda rather than a desire to spread the virus indiscriminately.