Operation Sharpshooter — APT Profile

Operation Sharpshooter is a global cyber espionage campaign first documented by McAfee in December 2018, targeting nuclear, defense, energy and financial organizations. Intrusions used an in-memory implant to retrieve a second-stage modular backdoor that McAfee named Rising Sun, which was built on source code from Duuzer, a Lazarus Group backdoor first observed in 2015. McAfee initially declined to attribute the campaign, warning that the overlaps with Lazarus tooling were conspicuous enough to raise the possibility of deliberate false flags. Analysis of a seized command-and-control server, published in 2019, subsequently led McAfee to link the campaign to the Lazarus Group.

Tools & malware

Vendor research

Read the full analysis on IntelFusions