Skip to main content
Mallory
MalwareUsed by 2 actors

LastConn

LastConn is a malware implant associated with TA402, also known as Molerats, a likely Palestinian-aligned threat cluster operating in espionage campaigns. Reporting states that LastConn was discovered as part of TA402 activity and was assessed with high confidence to be an updated version of SharpStage. It is also described as a prior implant later likely replaced by the C# backdoor NimbleMamba. Based on direct comparisons in the reporting, LastConn shares traits with NimbleMamba including C# implementation, base64 encoding in its command-and-control framework, and use of the Dropbox API for command-and-control. Dropbox-linked infrastructure connections between LastConn and NimbleMamba were cited as supporting attribution to the same operators. LastConn has been referenced alongside other malware used by the same ecosystem, including BrittleBush and Micropsia, and is included in reporting on campaigns targeting Middle Eastern governments, foreign policy think tanks, a state-affiliated airline, and more broadly organizations in the Middle East and North Africa. High-confidence content does not provide standalone LastConn-specific infection chain details or indicators beyond its linkage to TA402/Molerats, its relationship to SharpStage and NimbleMamba, and its use of Dropbox-related C2 characteristics.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Molerats

Later in June 2021, the LastConn malware, which has been discovered as part of activities attributed to the TA402 cluster, was assessed with high confidence to be an updated version of SharpStage.

via sentinelone labssentinelone.com
aluminum_saratoga

Tools… “NimbleMamba, BrittleBush, LastConn, Micropsia”

via secureworks threat profilessecureworks.com
MITRE ATT&CK

Techniques & procedures

2 distinct techniques documented for this family, organized by ATT&CK tactic.

Stealth

1 technique
T1027Obfuscated Files or InformationEvidence1
TacticStealth

NimbleMamba is written in C# and delivered as an obfuscated .NET executable using third-party obfuscators.

T1071.001Web ProtocolsEvidence1

NimbleMamba uses the Dropbox API for both command and control as well as exfiltration.

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app4 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping2

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.