Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S1159
MITRE ATT&CK Malware

DUSTTRAP (S1159)

ShareXLinkedInRedditHN

[DUSTTRAP](https://attack.mitre.org/software/S1159) is a multi-stage plugin framework associated with [APT41](https://attack.mitre.org/groups/G0096) operations with multiple components.(Citation: Google Cloud APT41 2024)

Platforms: Windows

▪Techniques implemented (29)

T1087.002Domain AccountT1012Query RegistryT1615Group Policy DiscoveryT1055Process InjectionT1056.001KeyloggingT1070Indicator RemovalT1027.013Encrypted/Encoded FileT1057Process DiscoveryT1087.001Local AccountT1113Screen CaptureT1518.001Security Software DiscoveryT1140Deobfuscate/Decode Files or InformationT1105Ingress Tool TransferT1083File and Directory DiscoveryT1005Data from Local SystemT1016System Network Configuration DiscoveryT1059.003Windows Command ShellT1010Application Window DiscoveryT1070.005Network Share Connection RemovalT1041Exfiltration Over C2 ChannelT1124System Time DiscoveryT1482Domain Trust DiscoveryT1685.005Clear Windows Event LogsT1082System Information DiscoveryT1027.009Embedded PayloadsT1018Remote System DiscoveryT1654Log EnumerationT1497.001System ChecksT1135Network Share Discovery

▪Used by groups (1)

G0096APT41
S1159on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.