‘Operation Sharpshooter’ Targets Global Defense, Critical Infrastructure

2018-12-12 • Mcafee •

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/operation-sharpshooter-targets-global-defense-critical-infrastructure/

McAfee reported Operation Sharpshooter as a global campaign against nuclear, defense, energy, and financial organizations, with many observed Rising Sun infections in the United States and defense or government-related targets. The activity masqueraded as legitimate job recruitment and used weaponized documents or macros to download an in-memory next stage. Rising Sun gathered host and network intelligence and exfiltrated victim data to attacker C2; its framework reused source code from Lazarus Group's 2015 Duuzer backdoor, but McAfee warned the links could be false flags and did not make a final attribution. The report supports detection for multi-stage reconnaissance, remote access, and C2 patterns tied to job-themed payload delivery.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 37b04dcdcfdcaa885df0f392524db7a… 2018-12-12 2020-03-09
HASH 4135f92055dba1fedafe70a8e094623… 2018-12-12 2018-12-23
HASH 88a5287b6e9879e79240660408e2e86… 2018-12-12 2018-12-12
HASH 876886c8963e4f46e52de9a243f2225… 2018-12-12 2018-12-12
HASH f5d561e80808f32402321ba76cae6b9… 2018-12-12 2018-12-12
URL http://www.dropbox.com/s/2shp23… 2018-12-12 2018-12-12
DOMAIN kingkoil.com 2018-12-12 2018-12-12
IPv4 208.117.44.112 2018-12-12 2018-12-12
IPv4 137.74.41.56 2018-12-12 2018-12-12
IPv4 34.214.99.20 2018-12-12 2018-12-12

Related Reports

« Back