SharpJSHandler is a .NET malware agent used by the espionage threat actor Unfading Sea Haze between at least 2018 and 2023. Bitdefender described it as functioning like a web shell alternative: it listens for HTTP requests and executes encoded JavaScript code. Reported variants also used cloud storage services for command-and-control or communication, specifically Dropbox and OneDrive. SharpJSHandler was supported by a loader named Ps2dllLoader, which executed payloads in memory. In the broader Unfading Sea Haze intrusion set, this tooling was used in campaigns targeting primarily government and military organizations in South China Sea countries. The actor is assessed by Bitdefender as espionage-focused and likely aligned with Chinese interests. High-confidence associated behaviors from the same campaign include command execution, file and folder manipulation, file upload/download, and data harvesting through related backdoors, although the provided content specifically attributes SharpJSHandler itself to HTTP-based JavaScript execution and web-shell-like operation rather than all campaign capabilities. The content does not provide SharpJSHandler-specific hashes or other direct indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...and 'SharpJSHandler,' a web shell that listens for HTTP requests and executes encoded JavaScript code.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web shell that listens for HTTP requests and executes encoded JavaScript.
A .NET agent used by Unfading Sea Haze, supported by Ps2dllLoader to execute payloads in memory as part of espionage intrusions.
A .NET agent acting as a web-shell-like backdoor: executes encoded JScript via Microsoft.JScript upon receiving tasks, with variants using direct HTTP or polling cloud storage (Dropbox/OneDrive) for command-and-control and exfil of results.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.