Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Operation Sharpshooter

Operation Sharpshooter

TLP:CLEAR
Active

Description

The McAfee Advanced Threat Research team and McAfee Labs Malware Operations Group have discovered a new global campaign targeting nuclear, defense, energy, and financial companies, based on McAfee® Global Threat Intelligence. This campaign, Operation Sharpshooter, leverages an in-memory implant to download and retrieve a second-stage implant—which we call Rising Sun—for further exploitation. According to our analysis, the Rising Sun implant uses source code from the Lazarus Group’s 2015 backdoor Trojan Duuzer in a new framework to infiltrate these key industries. Operation Sharpshooter’s numerous technical links to the Lazarus Group seem too obvious to immediately draw the conclusion that they are responsible for the attacks, and instead indicate a potential for false flags. Our research focuses on how this actor operates, the global impact, and how to detect the attack. We shall leave attribution to the broader security community.

AI Analysis

· 1 week ago

Executive Summary

Operation Sharpshooter is a sophisticated cyber campaign targeting critical infrastructure sectors, including nuclear, defense, energy, and financial industries. The actor employs advanced in-memory implants, such as Rising Sun, derived from Lazarus Group code, suggesting potential ties to or inspiration from known state-sponsored groups. While direct attribution remains inconclusive due to possible false flag tactics, the campaign’s technical sophistication and sector-specific targeting indicate a high-level threat actor with strategic intent.

Goals & Targeting

The actor’s targeting of critical infrastructure sectors suggests a strategic objective focused on intelligence collection, disruption, or potential sabotage of vital services. By prioritizing nuclear, defense, energy, and financial institutions, the campaign may aim to gather sensitive data, compromise operational systems, or create opportunities for future exploitation. The use of Lazarus-linked code could imply either a direct connection to North Korean threat actors or an attempt to exploit the notoriety of the Lazarus Group to obfuscate the true source of the attack. This approach aligns with tactics used by groups seeking to conduct espionage or influence geopolitical outcomes through cyber operations.

Enhanced Description

Discovered by McAfee Advanced Threat Research, Operation Sharpshooter represents a coordinated effort to infiltrate globally significant industries through the deployment of an in-memory implant. This initial payload facilitates the download of a second-stage implant named Rising Sun, which incorporates source code from the Lazarus Group’s 2015 Duuzer backdoor. The use of such legacy code suggests either a direct link to Lazarus or deliberate mimicry to misattribute the attacks. The campaign’s focus on critical sectors—nuclear, defense, energy, and finance—highlights a strategic interest in compromising systems that underpin national security and economic stability. While the technical infrastructure shares similarities with known APT groups, the operators have not yet demonstrated the same level of operational persistence or long-term surveillance capabilities typically associated with state-sponsored actors. McAfee’s analysis emphasizes detection and mitigation strategies, deferring definitive attribution to broader security communities due to the potential use of false flags.

Key Capabilities

  • In-memory implant deployment for stealthy execution
  • Second-stage payload delivery via custom frameworks
  • Code reuse from known threat groups (e.g., Lazarus Group’s Duuzer backdoor)
  • Targeted exploitation of critical infrastructure sectors
  • Potential use of spear-phishing or other social engineering tactics for initial access

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access

ATT&CK Techniques

T1055.003 - Process Injection
T1059.003 - Command and Scripting Interpreter: PowerShell
T1566.001 - Phishing
T1105 - Remote Desktop Protocol (RDP) Usage
T1560.01 - Archive via FTP

Software / Tooling

Rising Sun (custom in-memory implant)
Duuzer (Lazarus Group backdoor, code-reused variant)
Potential use of Cobalt Strike for initial access

Campaigns & Victims

Operation Sharpshooter appears to be a relatively recent campaign with limited public disclosure of specific incidents, though its global reach is evident through targeting across multiple sectors. The operational tempo suggests a focus on rapid infiltration rather than prolonged persistence, with a clear emphasis on leveraging existing malware frameworks to avoid detection. Notable past operations linked to similar tactics include Lazarus Group campaigns targeting financial institutions and critical infrastructure, though direct ties remain unconfirmed. The campaign’s reliance on code reuse and potential false flagging indicates a tactical effort to confuse attribution and evade countermeasures.

IOC Patterns

  • Spear-phishing with malicious Office documents containing macro-based payloads
  • In-memory execution of second-stage implants (e.g., Rising Sun)
  • C2 communication via DNS tunneling or encrypted protocols
  • Staging of malicious payloads on bulletproof hosting services
  • Use of domain fronting techniques to mask command-and-control infrastructure

Recommended Actions

  • Implement advanced endpoint detection and response (EDR) tools to identify in-memory execution anomalies
  • Monitor network traffic for DNS tunneling or unusual outbound connections to known malicious domains
  • Conduct regular phishing simulations and employee training to mitigate social engineering risks
  • Deploy sandboxing solutions to analyze suspicious attachments and executables
  • Correlate threat intelligence feeds focusing on Lazarus Group and similar APT groups for proactive detection

Suggested Tags

APT
espionage
false flag
nuclear-sector
finance-sector
Lazarus-inspired

Confidence Assessment

The confidence in the technical linkage between Operation Sharpshooter and the Lazarus Group is moderate, based on code reuse and shared tactics. However, the lack of definitive attribution and the potential use of false flagging tactics introduce uncertainty. Additionally, limited public disclosure of specific campaigns and IOCs reduces the ability to confirm operational details such as full TTPs, actor motivations, and historical attack patterns. Further analysis of network traffic and forensic data from affected organizations is required to strengthen confidence in the assessment.

Intel Summary

0

Techniques

0

Tools

4

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Backdoor / C2
APT
espionage
false flag
nuclear-sector
finance-sector
Lazarus-inspired

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.