SUGARUSH

S1049

Malware.View on attack.mitre.org

About this malware

SUGARUSH is a small custom backdoor that can establish a reverse shell over TCP to a hard coded C2 address. SUGARUSH was first identified during analysis of UNC3890's C0010 campaign targeting Israeli companies, which began in late 2020.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1016.001
Internet Connection Discovery

SUGARUSH has checked for internet connectivity from an infected host before attempting to establish a new TCP connection.

T1059.003
Windows Command Shell

SUGARUSH has used `cmd` for execution on an infected host.

T1095
Non-Application Layer Protocol

SUGARUSH has used TCP for C2.

T1543.003
Windows Service

SUGARUSH has created a service named `Service1` for persistence.

T1571
Non-Standard Port

SUGARUSH has used port 4585 for a TCP connection to its C2.

T1680
Local Storage Discovery

MoonWind can obtain the number of drives on the victim machine.

Groups that use it0

None recorded.

Campaigns1

References1

  1. Mandiant UNC3890 Aug 2022 Open source
    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.