For Operation Dust Storm, the threat actors used UPX to pack some payloads.3
campaign
Operation Dust Storm C0016
- First seen
- January 2010
- Last seen
- February 2016
- Created
- 29 September 2022
- Last modified
- 31 July 2026
Operation Dust Storm was a long-standing persistent cyber espionage campaign that targeted multiple industries in Japan, South Korea, the United States, Europe, and several Southeast Asian countries. By 2015, the Operation Dust Storm threat actors shifted from government and defense-related intelligence targets to Japanese companies or Japanese subdivisions of larger foreign organizations supporting Japan's critical infrastructure, including electricity generation, oil and natural gas, finance, transportation, and construction.[1]
Operation Dust Storm threat actors also began to use Android backdoors in their operations by 2015, with all identified victims at the time residing in Japan or South Korea.[2]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference C0016
During Operation Dust Storm, the threat actors encoded some payloads with a single-byte XOR, both skipping the key itself and zeroing in an attempt to avoid exposing the key; other payloads were Base64-encoded.4
For Operation Dust Storm, the threat actors disguised some executables as JPG files.5
During Operation Dust Storm, the threat actors used Visual Basic scripts.6
During Operation Dust Storm, the threat actors used JavaScript code.7
During Operation Dust Storm, attackers used VBS code to decode payloads.8
Standing C0016
Reach is how much of ATT&CK this campaign touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 56 ATT&CK campaigns only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
50th percentile · 50% of 56 ATT&CK campaigns have more Enterprise techniques.
34th percentile · 66% of 56 ATT&CK campaigns have more tactics spanned.
88th percentile · 88% of 56 ATT&CK campaigns have this many tools and malware or fewer.
55% of the population shares a single value across only 3 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
50th percentile · 50% of 56 ATT&CK campaigns have more detection rules per technique.
Detection coverage C0016
316 distinct rules cover the 17 techniques recorded for this campaign. The 367 technique-to-rule mappings resolve to 316 distinct rules, because one rule can cover several techniques. 204 Sigma · 112 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org