Shark is a Windows backdoor associated with the Iranian threat cluster tracked as Lyceum, also known as Hexane and SiameseKitten, and linked by multiple researchers to OilRig/APT34 activity. It emerged as a successor to DanBot in Lyceum intrusion chains and was observed in 2021 targeting organizations including Israeli IT and communications companies, with broader victimology tied to diplomatic, technology, and medical entities in the Middle East and North Africa. The malware has also been referenced in unrelated contexts as a Linux scanning tool and as a ransomware brand, but the best-supported usage identifies Shark as a .NET backdoor used for espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Linux hacking tool 'Shark' was found within these files.
Through cross-referencing findings from the campaign, we identified this malware as a substitute for DanBot. According to one of the files’ PDB path, the malware is named “Shark”, a name we adopted.
Major tools we attribute to Lyceum include DanBot, the Shark, Milan, and Marlin backdoors...
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
The victim is contacted through social media. In this instance, the profile is impersonating a manager from ChipPc’s HR department... The victim is then directed to a website that is embedded with malware and is designed to impersonate the company’s legitimate website.
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The attack script first conducts SYN scanning to check if a specific port is open. It also reads the banner information of the response from the host.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Examples in the content include malware extracting or unpacking ZIP, RAR, CAB, tar.gz, and other archived content, such as 'Emotet has used a self-extracting RAR file to deliver modules to victims' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
Marlin makes use of Microsoft's OneDrive API for its C2 operations. | The ToneDeaf backdoor primarily communicated with its C&C over HTTP/S but included a secondary method, DNS tunneling, which does not function properly," the researchers said. "Shark has similar symptoms, where its primary communication method uses DNS but has a non-functional HTTP/S secondary option.
Initially, HTTP requests are sent to the C&C domain to download a malicious payload.
Application Layer Protocol: DNS – T107.004. Siamesekitten uses DNS Tunneling to communicate with the malware.
The Milan backdoor malware infects the computer or server after one or more lure files are downloaded... The DanBot RAT is downloaded to the infected system.
Data Encoding: Non-Standard Encoding – T1132.002. Siamesekitten encodes the data that is sent to the C2 based on their own protocol.
Remote Access Trojans are programs that provide the capability to allow covert surveillance or the ability to gain unauthorized access to a victim PC... they provide the capability for an attacker to gain unauthorized remote access to the victim machine via specially configured communication protocols which are set up upon initial infection of the victim computer.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a malware/tool name in a collection of SHA-256 hashes intended to help identify C2 infrastructure, open directories, and phishing assets.
A backdoor attributed to the Lyceum subgroup within OilRig, referenced as part of related tooling.
Named as an example of earlier public ransomware-as-a-service offerings.
Backdoor attributed to Lyceum/OilRig; referenced as co-deployed with downloaders in Israeli targets (no further technical detail here).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.