Operation Sharpshooter is a named intrusion campaign characterized in available reporting by the staging of malicious files on Dropbox and other websites to support malware delivery. The campaign’s documented tradecraft in the available evidence centers on use of third-party and web-hosted infrastructure for payload staging and follow-on download, indicating an emphasis on leveraging externally hosted resources to facilitate victim access to malicious content and reduce operational friction. Attribution, origin, victimology, sector focus, and broader operational objectives are not established at high confidence from the available facts, and no corroborated sub-groups or alternative actor identities are confirmed beyond the campaign naming.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign involving staging malicious files on Dropbox and other sites for delivery.
Campaign involving staging malicious files on Dropbox and other websites.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.