Sage is a malware name used for at least two distinct threat contexts. Most commonly, it refers to a Windows ransomware family, including Sage 2.0, that has been described as related to or a variant of CryLocker. In ransomware operations, Sage has been delivered through malicious spam campaigns using ZIP attachments that contain either macro-enabled Word documents or JavaScript downloaders, with some campaigns using double-zipped attachments. It has also been distributed by the financially motivated threat actor Storm-0324, which historically delivered Sage alongside other crimeware through phishing and exploit-kit-driven infection chains.
On infected Windows systems, Sage encrypts files, appends a dedicated extension, changes the desktop background to ransom instructions, and drops ransom notes both on the desktop and in directories containing encrypted data. Observed behavior includes repeated user account control prompts during execution, persistence via scheduled tasks, and storage of its executable in user profile locations. Post-infection communications have included HTTP callback traffic and, in some reporting, large-scale UDP traffic assessed as possible encoded or encrypted peer-to-peer communications. These characteristics support classification as ransomware with persistence and defense-evasion-related execution behavior.
Separately, Sage is also the name applied to a Java-based intrusion toolset used in Oracle E-Business Suite compromises associated with exploitation activity linked to the Cl0p extortion ecosystem and suspected FIN11-related operations. In that context, components including Sagegift, Sageleaf, and Sagewave have been used after exploitation to load in-memory payloads, install a malicious Java servlet filter, maintain access, and execute commands within compromised Oracle E-Business Suite environments. This Oracle-focused Sage toolchain is distinct in function and platform from the Windows ransomware family but shares the same naming convention in reporting. Because the supplied name is simply "sage," the term is ambiguous and encompasses both a Windows ransomware family and a Java post-exploitation framework used in Oracle E-Business Suite intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... Sage ransomware
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named infection chain/tooling referenced as part of repeatable attacker tradecraft built to exploit Oracle EBS architecture.
Multi-stage web shell infection chain used post-exploitation to maintain access; details of capabilities beyond web shelling are not provided here.
Sage is a set of Java-based payloads used in Oracle EBS attacks, including Sagegift (loader), Sageleaf (in-memory dropper), and Sagewave (malicious servlet filter). These components enable attackers to execute commands and deploy additional malicious code within the compromised environment.
Sage is a set of Java-based payloads used in Oracle EBS attacks, including Sagegift (loader), Sageleaf (in-memory dropper), and Sagewave (malicious servlet filter). These components enable attackers to execute commands and deploy additional malicious code within compromised environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.