SUGARUSH
MITRE ATT&CK: S1049 View on attack.mitre.org
Aliases: SUGARUSH
- First seen
- 2020-09-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:29:55
Targeted industries: technology-and-telecommunications government-and-public-sector
Targeted regions: country_code:il
Context
SUGARUSH is a small custom backdoor that can establish a reverse shell over TCP to a hard coded C2 address. SUGARUSH was first identified during analysis of UNC3890's C0010 campaign targeting Israeli companies, which began in late 2020.
Detection coverage
- 1 YARA rules
- 73 Sigma rules
Malware & tools used
- Local Storage Discovery (attack-pattern)
- Non-Standard Port (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- Windows Service (attack-pattern)
- Windows Command Shell (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
Used by threat actors
- C0010 (campaign)
Detection rules
- SEKOIA_Apt_Ir_Sugarush_Implant (yara-rule)
Reports & references
- Mandiant — Suspected Iranian Actor Targeting Israeli Shipping (report)
- MITRE ATT&CK — S1049 (report)