LastConn is a .NET backdoor associated with the Palestinian-aligned espionage group Molerats, also tracked as TA402 and commonly linked to the broader Gaza Cybergang ecosystem. It has been assessed as an updated successor to SharpStage and was later superseded by NimbleMamba. The malware has been used in targeted intelligence-collection operations against Middle Eastern government organizations and other entities with diplomatic or policy relevance in the region, including victims in countries such as Israel, the United Arab Emirates, and Turkey.
LastConn has been delivered through spearphishing campaigns and is tied to operations focused on exfiltrating sensitive information. Its functionality and tradecraft overlap with SharpStage, including implementation in .NET, use of the Dropbox API for communications, and checks related to Arabic-language environments that help constrain execution to intended victims. Public analysis also notes obfuscation and anti-analysis measures including .NET Reactor protection, encrypted strings, control-flow obfuscation, junk code, and a date-based execution guard in at least one analyzed sample.
Operationally, LastConn is best characterized as a targeted espionage implant used for persistent remote access and data theft rather than broad criminal deployment. Reporting links it to the same operator set that later adopted NimbleMamba, with technical continuity across tooling and infrastructure usage supporting that relationship.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat
...resulting in the development of NimbleMamba, which is designed to replace LastConn, which, in turn, is believed to be an upgraded version of another backdoor called SharpStage...
6 distinct techniques documented for this family, organized by ATT&CK tactic.
One of the discovered samples utilised an obfuscator that De4Dot could not successfully deobfuscate, known as .NET Reactor... the main methods of protection in this binary surround the string encryption and control flow obfuscation, as well as the addition of junk code.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the ALUMINUM SARATOGA threat profile.
Malware discovered in TA402-attributed activity and assessed with high confidence to be an updated version of SharpStage.
LastConn is a previously used implant by TA402 (Molerats) for espionage and remote access, now likely replaced by NimbleMamba in recent campaigns.
A backdoor previously used by Molerats that NimbleMamba is designed to replace; described as an upgraded version of SharpStage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.