SUGARDUMP

MITRE ATT&CK: S1042 View on attack.mitre.org

Aliases: SUGARDUMP

First seen
2021-01-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:06:52

Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace

Targeted regions: country_code:us country_code:il

Context

SUGARDUMP is a proprietary browser credential harvesting tool that was used by UNC3890 during the C0010 campaign. The first known SUGARDUMP version was used since at least early 2021, a second SMTP C2 version was used from late 2021-early 2022, and a third HTTP C2 variant was used since at least April 2022.

Detection coverage

  • 2 YARA rules
  • 147 Sigma rules

Malware & tools used

  • File and Directory Discovery (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Software Discovery (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Browser Information Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Malicious File (attack-pattern)
  • Mail Protocols (attack-pattern)
  • Archive via Custom Method (attack-pattern)

Used by threat actors

  • C0010 (campaign)

Detection rules

  • SEKOIA_Apt_Sugardump_Credentials_Stealer_Smtp (yara-rule)
  • SEKOIA_Apt_Sugardump_Credentials_Stealer_Http (yara-rule)

Reports & references

  • Mandiant — Suspected Iranian Actor Targeting Israeli Shipping (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Sugardump (report)
  • MITRE ATT&CK — S1042 (report)
  • Mandiant — Suspected Iranian Actor Targeting Israeli Shipping (report)

External references