ATT&CKSoftwareSHARPSTATS

SHARPSTATS

S0450

Malware.View on attack.mitre.org

About this malware

SHARPSTATS is a .NET backdoor used by MuddyWater since at least 2019.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1016
System Network Configuration Discovery

SHARPSTATS has the ability to identify the domain of the compromised host.

T1027.010
Command Obfuscation

SHARPSTATS has used base64 encoding and XOR to obfuscate PowerShell scripts.

T1033
System Owner/User Discovery

SHARPSTATS has the ability to identify the username on the compromised host.

T1059.001
PowerShell

SHARPSTATS has the ability to employ a custom PowerShell script.

T1082
System Information Discovery

SHARPSTATS has the ability to identify the IP address, machine name, and OS of the compromised host.

T1105
Ingress Tool Transfer

SHARPSTATS has the ability to upload and download files.

T1124
System Time Discovery

SHARPSTATS has the ability to identify the current date and time on the compromised host.

Groups that use it1

Campaigns0

None recorded.

References1

  1. TrendMicro POWERSTATS V3 June 2019 Open source
    Lunghi, D. and Horejsi, J.. (2019, June 10). MuddyWater Resurfaces, Uses Multi-Stage Backdoor POWERSTATS V3 and New Post-Exploitation Tools. Retrieved May 14, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.