The McAfee Advanced Threat Research team and McAfee Labs Malware Operations Group have discovered a new global campaign targeting nuclear, defense, energy, and financial companies, based on McAfee® Global Threat Intelligence. This campaign, Operation Sharpshooter, leverages an in-memory implant to download and retrieve a second-stage implant—which we call Rising Sun—for further exploitation. According to our analysis, the Rising Sun implant uses source code from the Lazarus Group’s 2015 backdoor Trojan Duuzer in a new framework to infiltrate these key industries. Operation Sharpshooter’s numerous technical links to the Lazarus Group seem too obvious to immediately draw the conclusion that they are responsible for the attacks, and instead indicate a potential for false flags. Our research focuses on how this actor operates, the global impact, and how to detect the attack. We shall leave attribution to the broader security community.
Executive Summary
Operation Sharpshooter is a sophisticated cyber campaign targeting critical infrastructure sectors, including nuclear, defense, energy, and financial industries. The actor employs advanced in-memory implants, such as Rising Sun, derived from Lazarus Group code, suggesting potential ties to or inspiration from known state-sponsored groups. While direct attribution remains inconclusive due to possible false flag tactics, the campaign’s technical sophistication and sector-specific targeting indicate a high-level threat actor with strategic intent.
Goals & Targeting
The actor’s targeting of critical infrastructure sectors suggests a strategic objective focused on intelligence collection, disruption, or potential sabotage of vital services. By prioritizing nuclear, defense, energy, and financial institutions, the campaign may aim to gather sensitive data, compromise operational systems, or create opportunities for future exploitation. The use of Lazarus-linked code could imply either a direct connection to North Korean threat actors or an attempt to exploit the notoriety of the Lazarus Group to obfuscate the true source of the attack. This approach aligns with tactics used by groups seeking to conduct espionage or influence geopolitical outcomes through cyber operations.
Enhanced Description
Discovered by McAfee Advanced Threat Research, Operation Sharpshooter represents a coordinated effort to infiltrate globally significant industries through the deployment of an in-memory implant. This initial payload facilitates the download of a second-stage implant named Rising Sun, which incorporates source code from the Lazarus Group’s 2015 Duuzer backdoor. The use of such legacy code suggests either a direct link to Lazarus or deliberate mimicry to misattribute the attacks. The campaign’s focus on critical sectors—nuclear, defense, energy, and finance—highlights a strategic interest in compromising systems that underpin national security and economic stability. While the technical infrastructure shares similarities with known APT groups, the operators have not yet demonstrated the same level of operational persistence or long-term surveillance capabilities typically associated with state-sponsored actors. McAfee’s analysis emphasizes detection and mitigation strategies, deferring definitive attribution to broader security communities due to the potential use of false flags.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Operation Sharpshooter appears to be a relatively recent campaign with limited public disclosure of specific incidents, though its global reach is evident through targeting across multiple sectors. The operational tempo suggests a focus on rapid infiltration rather than prolonged persistence, with a clear emphasis on leveraging existing malware frameworks to avoid detection. Notable past operations linked to similar tactics include Lazarus Group campaigns targeting financial institutions and critical infrastructure, though direct ties remain unconfirmed. The campaign’s reliance on code reuse and potential false flagging indicates a tactical effort to confuse attribution and evade countermeasures.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the technical linkage between Operation Sharpshooter and the Lazarus Group is moderate, based on code reuse and shared tactics. However, the lack of definitive attribution and the potential use of false flagging tactics introduce uncertainty. Additionally, limited public disclosure of specific campaigns and IOCs reduces the ability to confirm operational details such as full TTPs, actor motivations, and historical attack patterns. Further analysis of network traffic and forensic data from affected organizations is required to strengthen confidence in the assessment.
No techniques linked yet.
No tools linked yet.
Operation Sharpshooter
Global espionage campaign targeting nuclear, defense, energy, and financial sectors attributed to Lazarus Group.
Mar 1, 2019
TLP:AMBEROperation Sharpshooter
Global espionage campaign targeting nuclear, defense, energy, and financial sectors attributed to Lazarus Group.
Mar 1, 2019
TLP:AMBERNo observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
4
Campaigns
0
IOCs
0
Observed Data
0
Tactics