SUGARDUMP

S1042

Malware.View on attack.mitre.org

About this malware

SUGARDUMP is a proprietary browser credential harvesting tool that was used by UNC3890 during the C0010 campaign. The first known SUGARDUMP version was used since at least early 2021, a second SMTP C2 version was used from late 2021-early 2022, and a third HTTP C2 variant was used since at least April 2022.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1036.004
Masquerade Task or Service

SUGARDUMP's scheduled task has been named `MicrosoftInternetExplorerCrashRepoeterTaskMachineUA` or `MicrosoftEdgeCrashRepoeterTaskMachineUA`, depending on the Windows OS version.

T1036.005
Match Legitimate Resource Name or Location

SUGARDUMP has been named `CrashReporter.exe` to appear as a legitimate Mozilla executable.

T1041
Exfiltration Over C2 Channel

SUGARDUMP has sent stolen credentials and other data to its C2 server.

T1053.005
Scheduled Task

SUGARDUMP has created scheduled tasks called `MicrosoftInternetExplorerCrashRepoeterTaskMachineUA` and `MicrosoftEdgeCrashRepoeterTaskMachineUA`, which were configured to execute `CrashReporter.exe` during user logon.

T1071.001
Web Protocols

A SUGARDUMP variant has used HTTP for C2.

T1071.003
Mail Protocols

A SUGARDUMP variant used SMTP for C2.

T1074.001
Local Data Staging

SUGARDUMP has stored collected data under `%<malware_execution_folder>%\\CrashLog.txt`.

T1083
File and Directory Discovery

SUGARDUMP can search for and collect data from specific Chrome, Opera, Microsoft Edge, and Firefox files, including any folders that have the string `Profile` in its name.

T1204.002
Malicious File

Some SUGARDUMP variants required a user to enable a macro within a malicious .xls file for execution.

T1217
Browser Information Discovery

SUGARDUMP has collected browser bookmark and history information.

T1518
Software Discovery

SUGARDUMP can identify Chrome, Opera, Edge Chromium, and Firefox browsers, including version number, on a compromised host.

T1555.003
Credentials from Web Browsers

SUGARDUMP variants have harvested credentials from browsers such as Firefox, Chrome, Opera, and Edge.

T1560.003
Archive via Custom Method

SUGARDUMP has encrypted collected data using AES CBC mode and encoded it using Base64.

Groups that use it0

None recorded.

Campaigns1

References1

  1. Mandiant UNC3890 Aug 2022 Open source
    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.