S1049Windows

S1049SUGARUSH

Platforms
1
ATT&CK
14.1
References
2

Description

[SUGARUSH](https://attack.mitre.org/software/S1049) is a small custom backdoor that can establish a reverse shell over TCP to a hard coded C2 address. [SUGARUSH](https://attack.mitre.org/software/S1049) was first identified during analysis of UNC3890's [C0010](https://attack.mitre.org/campaigns/C0010) campaign targeting Israeli companies, which began in late 2020.(Citation: Mandiant UNC3890 Aug 2022)

Platforms· 1

Windows

References

  1. https://attack.mitre.org/software/S1049
  2. https://www.mandiant.com/resources/blog/suspected-iranian-actor-targeting-israeli-shipping

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
SUGARDUMP
Actor
UNC3890
Software
Shark
Software
BADHATCH
Software
Chinoxy
Software
EVILNUM
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.