Campaign, Sep 2017 to Mar 2019.View on attack.mitre.org
Operation Sharpshooter was a global cyber espionage campaign that targeted nuclear, defense, government, energy, and financial companies, with many located in Germany, Turkey, the United Kingdom, and the United States. Security researchers noted the campaign shared many similarities with previous Lazarus Group operations, including fake job recruitment lures and shared malware code.
| Technique | Procedure example |
|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
During Operation Sharpshooter, threat actors installed Rising Sun in the Startup folder and disguised it as `mssync.exe`. |
| T1055 Process Injection |
During Operation Sharpshooter, threat actors leveraged embedded shellcode to inject a downloader into the memory of Word. |
| T1059.005 Visual Basic |
During Operation Sharpshooter, the threat actors used a VBA macro to execute a simple downloader that installed Rising Sun. |
| T1090 Proxy |
For Operation Sharpshooter, the threat actors used the ExpressVPN service to hide their location. |
| T1105 Ingress Tool Transfer |
During Operation Sharpshooter, additional payloads were downloaded after a target was infected with a first-stage downloader. |
| T1106 Native API |
During Operation Sharpshooter, the first stage downloader resolved various Windows libraries and APIs, including `LoadLibraryA()`, `GetProcAddress()`, and `CreateProcessA()`. |
| T1204.002 Malicious File |
During Operation Sharpshooter, the threat actors relied on victims executing malicious Microsoft Word or PDF files. |
| T1547.001 Registry Run Keys / Startup Folder |
During Operation Sharpshooter, a first-stage downloader installed Rising Sun to `%Startup%\mssync.exe` on a compromised host. |
| T1559.002 Dynamic Data Exchange |
During Operation Sharpshooter, threat actors sent malicious Word OLE documents to victims. |
| T1583.006 Web Services |
For Operation Sharpshooter, the threat actors used Dropbox to host lure documents and their first-stage downloader. |
| T1584.004 Server |
For Operation Sharpshooter, the threat actors compromised a server they used as part of the campaign's infrastructure. |
| T1587.001 Malware |
For Operation Sharpshooter, the threat actors used the Rising Sun modular backdoor. |
| T1608.001 Upload Malware |
For Operation Sharpshooter, the threat actors staged malicious files on Dropbox and other websites. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.