Sharpire is a .NET backdoor for Windows that supports the open-source PowerShell Empire post-exploitation framework. It provides remote system control through PowerShell command execution, directory listing and navigation, file copying and movement, and deletion of files or directories. Its reconnaissance functions retrieve network configuration, routing tables, process information, the current user, and the hostname. It can also reboot or shut down an infected system.
Sharpire is associated with Kinsing, also known as H2Miner, through attacker infrastructure used in campaigns exploiting the Apache ActiveMQ remote code execution vulnerability CVE-2023-46604. These campaigns have targeted vulnerable servers in South Korea and used malicious XML configurations to execute commands and install downloader stagers. Sharpire was hosted on the attackers’ download infrastructure, extending their available tooling beyond cryptocurrency mining to remote control and post-exploitation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-46604 allows remote attackers with network access to a broker to execute arbitrary shell commands. This is achieved by exploiting serialized class types within the OpenWire protocol, which, in turn, leads to the broker instantiating any class available on the classpath.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor added as an additional stage in intrusions associated with Kinsing, enabling multi-stage compromise.
.NET backdoor supporting PowerShell Empire, used in conjunction with cryptojacking campaigns and other post-exploitation frameworks.
Sharpire is a .NET-based backdoor that integrates with PowerShell Empire, providing remote access and post-exploitation capabilities such as command execution, file manipulation, and system information gathering.
.NET backdoor compatible with PowerShell Empire, found on the attacker's download server. It supports PowerShell execution, file operations, system and network reconnaissance, and reboot or shutdown commands. The researchers assess that Kinsing used it to control infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.