Sardonic
MITRE ATT&CK: S1085 View on attack.mitre.org
Aliases: Sardonic
- First seen
- 2021-08-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:21:29
Targeted industries: financial-services
Targeted regions: country_code:us
Context
Sardonic is a backdoor written in C and C++ that is known to be used by FIN8, as early as August 2021 to target a financial institution in the United States. Sardonic has a plugin system that can load specially made DLLs and execute their functions.
Detection coverage
- 566 Sigma rules
Malware & tools used
- Command Obfuscation (attack-pattern)
- System Information Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Windows Management Instrumentation Event Subscription (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Network Share Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Data from Local System (attack-pattern)
- Windows Command Shell (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Non-Standard Port (attack-pattern)
- Process Discovery (attack-pattern)
- System Service Discovery (attack-pattern)
- Native API (attack-pattern)
- Standard Encoding (attack-pattern)
- Indicator Removal (attack-pattern)
- Reflective Code Loading (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- PowerShell (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Asynchronous Procedure Call (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
Used by threat actors
- FIN8 (threat-actor)
Reports & references
- Broadcom/Symantec — Syssphinx Fin8 Backdoor (report)
- bitdefender.com — Bitdefender Pr Whitepaper Fin8 Creat5619 En En (report)
- MITRE ATT&CK — S1085 (report)