The Rise of Dustman: Data-Wiping Cyberattacks Traced to Iran
- Actor Motivations: Sabotage
- Attack Vectors: Wiper
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
The Dustman is a data-wiping malware believed to be of Iranian origin, characterized by its use of shared code with another wiper called "ZeroCleare." It exhibits features of blatant copy-pasting from a GitHub repository without credit. The malware includes a muldrop executable containing three encrypted files: a VirtualBox driver from WinNT/Turla, a modified Eldos RawDisk driver, and a malware agent application. The agent application wipes data using the string "Down With Saudi Kingdom Down With Bin Salman." The initial dropper is a modified version of the TDL (Furutaka) project, indicating that the malware targets entities with connections to Saudi Arabia, exploiting vulnerabilities in internet-facing applications.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Region | Saudi Arabia | Verified |
Extracted IOCs
- 20d61c337653392ea472352931820dc60c37b2bc
- 7c1b25518dee1e30b5a6eaa1ea8e4a3780c24d0c
- a7133c316c534d1331c801bbcd3f4c62141013a1
- e3ae32ebe8465c7df1225a51234f13e8a44969cc
Tip: 4 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 4 file hash) to this threat have been found.
Overlaps
Source: IBM - January 2020
Detection (three cases): 20d61c337653392ea472352931820dc60c37b2bc, 7c1b25518dee1e30b5a6eaa1ea8e4a3780c24d0c, a7133c316c534d1331c801bbcd3f4c62141013a1
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Dustman Malware
Security researchers identified a piece of destructive malware named "Dustman." This malicious software is designed to infiltrate systems, bypass standard security protections, and permanently wipe data from infected computer hard drives.
While some cybersecurity reports and media outlets have attributed this malware to Iranian state-sponsored hackers, the exact origin remains heavily debated. The malware's creators heavily copy-pasted existing, free code from the internet and left highly obvious political messages, leading some analysts to suspect it could be a low-budget effort or a "false flag" designed to misdirect blame.
The primary goal of Dustman is pure destruction rather than espionage or financial theft. By erasing the hard drives of infected machines, the attackers aim to cause significant operational disruption and data loss for the victims.
The technical analysis primarily focuses on the specific mechanisms of the malware itself rather than a comprehensive list of victims. However, the reliance on a specific software trick suggests the attackers focused on targets where they could exploit administrative access to deploy the wiper.
Yes, the malware contains deeply embedded political messages, such as "Down With Saudi Kingdom Down With Bin Salman." This strongly indicates that the attackers specifically targeted Saudi Arabian entities, interests, or infrastructure for geopolitical reasons.
The attackers packaged their destructive tools inside a "dropper" program. Once launched, this program unpacks hidden files and exploits a legitimate software driver to sneak into the deepest, most protected levels of the operating system, allowing it to forcefully erase the disk without interference.
Given the aggressive political statements written directly into the malware's code, the targeted entities were likely chosen as part of an informational warfare campaign. The goal is to inflict maximum operational damage to send a political message.
Organizations should ensure that their systems are monitored for unusual, deep-level operating system activity and restrict "administrator" rights, as this malware fails to run without them. Additionally, security teams can search for specific digital fingerprints left by the malware, such as its unique internal naming conventions.
Because of the specific political messages and the destructive nature of the payload, this appears to be a highly targeted attack rather than a widespread threat meant to infect the general public. It is designed for specific geopolitical sabotage.