SHARPSTATS is a .NET backdoor associated with MuddyWater operations observed in 2019. It supports core remote-access functions including downloading files or payloads, uploading data, and executing commands or additional content on compromised systems. Reported behavior also includes host reconnaissance such as identifying the current username, domain, and local date and time, as well as the ability to execute custom PowerShell scripts. Its PowerShell components have been obfuscated with Base64 encoding and XOR, indicating an emphasis on defense evasion and flexible post-compromise tasking.
SHARPSTATS forms part of a broader MuddyWater malware ecosystem that has included POWERSTATS, CLOUDSTATS, and DELPHSTATS, alongside extensive use of PowerShell-based tradecraft and open-source post-exploitation tooling. MuddyWater has primarily targeted government entities, telecommunications organizations, and related sectors across the Middle East and Asia, with later expansion into Europe. In this context, SHARPSTATS is best characterized as a Windows-focused backdoor used for post-exploitation access, host profiling, and operator-driven execution of follow-on actions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In January 2019, we discovered that the campaign started using SHARPSTATS... a .NET-written backdoor that supports DOWNLOAD, UPLOAD, and RUN functions.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
"Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "ADVSTORESHELL... strings... encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed." / "APT29 has used encoded PowerShell commands." / "APT41 used VMProtected binaries..."
APT19 used Base64 to obfuscate executed commands; APT32 used Invoke-Obfuscation to obfuscate PowerShell; Aquatic Panda encoded PowerShell commands in Base64; numerous groups and malware used Base64, XOR, RC4, compression, encryption, variable substitution, and other methods to obfuscate scripts and commands.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that identifies the username on the compromised host.
Malware that can employ custom PowerShell scripts.
Identifies the domain of compromised hosts.
Identifies the username on the compromised host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.