SUGARUSH

MITRE ATT&CK: S1049 View on attack.mitre.org

Aliases: SUGARUSH

First seen
2020-09-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:29:55

Targeted industries: technology-and-telecommunications government-and-public-sector

Targeted regions: country_code:il

Context

SUGARUSH is a small custom backdoor that can establish a reverse shell over TCP to a hard coded C2 address. SUGARUSH was first identified during analysis of UNC3890's C0010 campaign targeting Israeli companies, which began in late 2020.

Detection coverage

  • 1 YARA rules
  • 73 Sigma rules

Malware & tools used

  • Local Storage Discovery (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • Windows Service (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)

Used by threat actors

  • C0010 (campaign)

Detection rules

  • SEKOIA_Apt_Ir_Sugarush_Implant (yara-rule)

Reports & references

  • Mandiant — Suspected Iranian Actor Targeting Israeli Shipping (report)
  • MITRE ATT&CK — S1049 (report)

External references