‘Operation Sharpshooter’ Targets Global Defense, Critical Infrastructure
2018-12-12 • Mcafee •
McAfee reported Operation Sharpshooter as a global campaign against nuclear, defense, energy, and financial organizations, with many observed Rising Sun infections in the United States and defense or government-related targets. The activity masqueraded as legitimate job recruitment and used weaponized documents or macros to download an in-memory next stage. Rising Sun gathered host and network intelligence and exfiltrated victim data to attacker C2; its framework reused source code from Lazarus Group's 2015 Duuzer backdoor, but McAfee warned the links could be false flags and did not make a final attribution. The report supports detection for multi-stage reconnaissance, remote access, and C2 patterns tied to job-themed payload delivery.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 37b04dcdcfdcaa885df0f392524db7a… | 2018-12-12 | 2020-03-09 |
| HASH | 4135f92055dba1fedafe70a8e094623… | 2018-12-12 | 2018-12-23 |
| HASH | 88a5287b6e9879e79240660408e2e86… | 2018-12-12 | 2018-12-12 |
| HASH | 876886c8963e4f46e52de9a243f2225… | 2018-12-12 | 2018-12-12 |
| HASH | f5d561e80808f32402321ba76cae6b9… | 2018-12-12 | 2018-12-12 |
| URL | http://www.dropbox.com/s/2shp23… | 2018-12-12 | 2018-12-12 |
| DOMAIN | kingkoil.com | 2018-12-12 | 2018-12-12 |
| IPv4 | 208.117.44.112 | 2018-12-12 | 2018-12-12 |
| IPv4 | 137.74.41.56 | 2018-12-12 | 2018-12-12 |
| IPv4 | 34.214.99.20 | 2018-12-12 | 2018-12-12 |