SUGARRUSH

Malware type
backdoor
Profile updated
2026-07-07 13:06:50

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications

Context

According to Mandiant, SUGARUSH is a backdoor written to establish a connection with an embedded C2 and to execute CMD commands.

Reports & references

  • Mandiant — Suspected Iranian Actor Targeting Israeli Shipping (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Sugarrush (report)

External references