ATT&CKCampaignsOperation Sharpshooter

Operation Sharpshooter

C0013

Campaign, Sep 2017 to Mar 2019.View on attack.mitre.org

About this campaign

Operation Sharpshooter was a global cyber espionage campaign that targeted nuclear, defense, government, energy, and financial companies, with many located in Germany, Turkey, the United Kingdom, and the United States. Security researchers noted the campaign shared many similarities with previous Lazarus Group operations, including fake job recruitment lures and shared malware code.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1036.005
Match Legitimate Resource Name or Location

During Operation Sharpshooter, threat actors installed Rising Sun in the Startup folder and disguised it as `mssync.exe`.

T1055
Process Injection

During Operation Sharpshooter, threat actors leveraged embedded shellcode to inject a downloader into the memory of Word.

T1059.005
Visual Basic

During Operation Sharpshooter, the threat actors used a VBA macro to execute a simple downloader that installed Rising Sun.

T1090
Proxy

For Operation Sharpshooter, the threat actors used the ExpressVPN service to hide their location.

T1105
Ingress Tool Transfer

During Operation Sharpshooter, additional payloads were downloaded after a target was infected with a first-stage downloader.

T1106
Native API

During Operation Sharpshooter, the first stage downloader resolved various Windows libraries and APIs, including `LoadLibraryA()`, `GetProcAddress()`, and `CreateProcessA()`.

T1204.002
Malicious File

During Operation Sharpshooter, the threat actors relied on victims executing malicious Microsoft Word or PDF files.

T1547.001
Registry Run Keys / Startup Folder

During Operation Sharpshooter, a first-stage downloader installed Rising Sun to `%Startup%\mssync.exe` on a compromised host.

T1559.002
Dynamic Data Exchange

During Operation Sharpshooter, threat actors sent malicious Word OLE documents to victims.

T1583.006
Web Services

For Operation Sharpshooter, the threat actors used Dropbox to host lure documents and their first-stage downloader.

T1584.004
Server

For Operation Sharpshooter, the threat actors compromised a server they used as part of the campaign's infrastructure.

T1587.001
Malware

For Operation Sharpshooter, the threat actors used the Rising Sun modular backdoor.

T1608.001
Upload Malware

For Operation Sharpshooter, the threat actors staged malicious files on Dropbox and other websites.

Attributed groups0

MITRE does not attribute this campaign to a group.

Software1

References3

  1. Bleeping Computer Op Sharpshooter March 2019 Open source
    I. Ilascu. (2019, March 3). Op 'Sharpshooter' Connected to North Korea's Lazarus Group. Retrieved September 26, 2022.
  2. McAfee Sharpshooter December 2018 Open source
    Sherstobitoff, R., Malhotra, A., et. al.. (2018, December 18). Operation Sharpshooter Campaign Targets Global Defense, Critical Infrastructure. Retrieved May 14, 2020.
  3. Threatpost New Op Sharpshooter Data March 2019 Open source
    L. O'Donnell. (2019, March 3). RSAC 2019: New Operation Sharpshooter Data Reveals Higher Complexity, Scope. Retrieved September 26, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.