Operation Sharpshooter is the name of a cyber espionage campaign discovered in October 2018 targeting nuclear, defense, energy, and financial companies. Though overlaps between this adversary and Lazarus Group have been noted, definitive links have not been established.(Citation: McAfee Sharpshooter December 2018)
ID: G0104
Associated Groups: 
Version: 1.0
Created: 14 May 2020
Last Modified: 26 Sep 2022

Associated Group Descriptions

Name Description

Techniques Used

Domain ID Name Use
Enterprise T1547 .001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Sharpshooter's first-stage downloader installed Rising Sun to the startup folder %Startup%\mssync.exe.(Citation: McAfee Sharpshooter December 2018)

Enterprise T1059 .005 Command and Scripting Interpreter: Visual Basic

Sharpshooter's first-stage downloader was a VBA macro.(Citation: McAfee Sharpshooter December 2018)

Enterprise T1559 .002 Inter-Process Communication: Dynamic Data Exchange

Sharpshooter has sent malicious Word OLE documents to victims.(Citation: McAfee Sharpshooter December 2018)

Enterprise T1566 .001 Phishing: Spearphishing Attachment

Sharpshooter has sent malicious attachments via emails to targets.(Citation: McAfee Sharpshooter December 2018)

Enterprise T1204 .002 User Execution: Malicious File

Sharpshooter has sent malicious DOC and PDF files to targets so that they can be opened by a user.(Citation: McAfee Sharpshooter December 2018)

