Executive Summary
Rising Sun is a modular backdoor used by advanced threat actors during Operation Sharpshooter to embed persistent access in high‑value organizations such as nuclear and defense firms. The malware’s code‑sharing with Lazarus Group’s Trojan Duuzer hints at complex stealth and exfiltration capabilities, posing an elevated risk for critical infrastructure. Key_capabilities':['Remote command execution via modular C&C','Persistence through scheduled tasks or registry run keys','Credential dumping and account discovery','Network reconnaissance scanning and discovery','Encrypted data exfiltration channels','Dynamic module download and installation','Targeted attacks on high‑value sectors'], recommended_actions':['Block known Rising Sun C2 domains/IPs and related port usage','Monitor outbound traffic for suspicious encrypted shells and non‑standard protocols','Enforce execution control policies to prevent unsigned binaries','Detect anomalous PowerShell or command‑line activity on endpoints','Regularly audit scheduled tasks, registry autorun entries and service configurations','Implement network segmentation and strict access controls for critical systems'], confidence_assessment':'The analysis is based primarily on a McAfee report and lacks full technical breakdowns; while the description of core behaviors and target industries is reliable, specific implementation details such as persistence vectors or complete command sets remain uncertain. Confidence in functional capabilities is medium, with gaps in variant evolution post‑2019. suggested_tags':['Backdoor','Modular Malware','Targeted Attacks','Industrial Control Systems','Lazarus Group','Operation Sharpshooter','High-Value Target','Command and Control','Credential Access'], mitre_techniques:['T1059','T1046','T1062','T1087','T1105','T1053','T1070']}
Enhanced Description
Rising Sun is a modular backdoor noted for its use in the Operation Sharpshooter campaign that targeted critical infrastructure between 2017 and 2019. The malware’s architecture allows attackers to dynamically import additional modules—such as remote shells, credential dumping payloads or exfiltration tools—over its command-and-control channel, giving operators the flexibility to tailor each infection according to mission needs. Security researchers found that Rising Sun leveraged source code from the Lazarus Group’s Trojan Duuzer, suggesting shared development practices and potentially similar persistence and stealth techniques. The backdoor was reported to have infected at least 87 organizations across a range of high‑value sectors including nuclear, defense, energy, and financial services. While the last publicly documented activity dates to late 2019, limited information indicates that Rising Sun maintained robust persistence mechanisms (e.g., scheduled tasks or registry run keys) and employed encrypted channels for command transmission. Its modularity also implies that attackers could upgrade functionality within compromised systems, enabling lateral movement and stealthy data exfiltration. Overall, Rising Sun represents a sophisticated supply‑chain or targeted attack tool designed to infiltrate critical facilities, maintain long‑term footholds, and facilitate large‑scale espionage or sabotage activities.
Rising Sun is a modular backdoor that was used extensively in Operation Sharpshooter between 2017 and 2019. Rising Sun infected at least 87 organizations around the world, including nuclear, defense, energy, and financial service companies. Security researchers assessed Rising Sun included some source code from Lazarus Group's Trojan Duuzer.(Citation: McAfee Sharpshooter December 2018)