SysUpdate
MITRE ATT&CK: S0663 View on attack.mitre.org
Aliases: HyperSSL, Soldier, FOCUSFJORD, Sysupdate, SysUpdate
- First seen
- 2020-01-01 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Operating systems
- windows, linux
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-06-28 13:14:29
- Profile updated
- 2026-07-07 12:39:16
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Targeted regions: country_code:cn country_code:us country_code:uk
Context
SysUpdate is a backdoor written in C++ that has been used by Threat Group-3390 since at least 2020.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to SysUpdate (S0663). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 2ada1b48457c169cf3f80e248190374102615e2c89b70e574fba4ddc09b5fcd5 | 2026-06-28 | 2 |
Detection coverage
- 6 YARA rules
- 576 Sigma rules
Malware & tools used
- DNS (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- System Service Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Standard Encoding (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- Code Signing (attack-pattern)
- Data from Local System (attack-pattern)
- Fileless Storage (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- System Information Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- Systemd Service (attack-pattern)
- File Deletion (attack-pattern)
- Modify Registry (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- DLL (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
Used by threat actors
- Threat Group-3390 (threat-actor)
Detection rules
- SEKOIA_Apt_Luckymouse_Sysupdate_Removing_Tool (yara-rule)
- SEKOIA_Backdoor_Lin_Sysupdate (yara-rule)
- SEKOIA_Luckymouse_Sysupdate_Payload (yara-rule)
- SEKOIA_Luckymouse_Sysupdate_Loader (yara-rule)
- SIGNATURE_BASE_APT_MAL_APT27_Rshell_Jul24 (yara-rule)
- MALPEDIA_Win_Hyperssl_Auto (yara-rule)
Reports & references
- Trend Micro — Iron Tiger Apt Updates Toolkit With Evolved Sysupdate Malware Va (report)
- Mandiant — Unc215 Chinese Espionage Campaign In Israel (report)
- Palo Alto Unit 42 — Emissary Panda Attacks Middle East Government Sharepoint Servers (report)
- web.archive.org — Summit Archive 1574947864 (report)
- Mandiant — Chinese Espionage Tactics (report)
- ESET — Eset Industry Report Government (report)
- Trend Micro — Iron Tiger Sysupdate Adds Linux Targeting (report)
- x.com — 1933565063736021372 (report)
- vblocalhost.com — Vb2020 Shank Piccolini (report)
- Mandiant — Unc215 Chinese Espionage Campaign In Israel (report)
- tra.gov.ae — Mtp39Tp6.Pdf (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Hyperssl (report)
- sstic.org — Sstic2021 Slides Taking Advantage Of Pe Metadata Or How To Complete Your Favorite Threat Actor Sample Collection Lunghi (report)
- twitter.com — 1594937054303236096 (report)
- norfolkinfosec.com — Emissary Panda Dll Backdoor (report)
- sstic.org — Sstic2021 Article Taking Advantage Of Pe Metadata Or How To Complete Your Favorite Threat Actor Sample Collection Lunghi (report)
- MITRE ATT&CK — S0663 (report)