ATT&CKSoftwareSharpStage

SharpStage

S0546

Malware.View on attack.mitre.org

About this malware

SharpStage is a .NET malware with backdoor capabilities.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1047
Windows Management Instrumentation

SharpStage can use WMI for execution.

T1053.005
Scheduled Task

SharpStage has a persistence component to write a scheduled task for the payload.

T1059.001
PowerShell

SharpStage can execute arbitrary commands with PowerShell.

T1059.003
Windows Command Shell

SharpStage can execute arbitrary commands with the command line.

T1082
System Information Discovery

SharpStage has checked the system settings to see if Arabic is the configured language.

T1102
Web Service

SharpStage has used a legitimate web service for evading detection.

T1105
Ingress Tool Transfer

SharpStage has the ability to download and execute additional payloads via a DropBox API.

T1113
Screen Capture

SharpStage has the ability to capture the victim's screen.

T1140
Deobfuscate/Decode Files or Information

SharpStage has decompressed data received from the C2 server.

T1547.001
Registry Run Keys / Startup Folder

SharpStage has the ability to create persistence for the malware using the Registry autorun key and startup folder.

T1614.001
System Language Discovery

SharpStage has been used to target Arabic-speaking users and used code that checks if the compromised machine has the Arabic language installed.

Groups that use it1

Campaigns0

None recorded.

References2

  1. BleepingComputer Molerats Dec 2020 Open source
    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.
  2. Cybereason Molerats Dec 2020 Open source
    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.