LastConn is a malware implant associated with TA402, also known as Molerats, a likely Palestinian-aligned espionage threat actor. Reporting states that LastConn was discovered as part of TA402 activity and was assessed with high confidence to be an updated version of SharpStage. Subsequent reporting indicates NimbleMamba was likely developed to replace LastConn, and that both malware families were linked to the same operators.
Based on the provided content, LastConn is a C#/.NET implant that shares traits with NimbleMamba, including base64 encoding in its command-and-control framework and use of the Dropbox API for command-and-control. Dropbox-linked infrastructure connections between LastConn, NimbleMamba deployment, and NimbleMamba exfiltration were cited as supporting attribution to the same actor. LastConn has been used in targeted spear-phishing campaigns conducted by TA402 against Middle Eastern governments, foreign policy think tanks, and a state-affiliated airline, with delivery chains involving malicious RAR archives, actor-controlled infrastructure, geofencing, and redirects to legitimate sites to evade detection and restrict payload delivery to intended regions.
The malware is part of a broader TA402/Molerats toolset that has been used in espionage operations focused on the Middle East and North Africa. The content also places LastConn among malware used by ALUMINUM SARATOGA, a cluster publicly associated with Molerats, Gaza Cybergang, TA402, APT-C-23, Arid Viper, and Desert Falcon. High-confidence indicators and infrastructure details in the provided content are limited for LastConn specifically, but the reporting directly ties it to Dropbox API-based C2 characteristics and to TA402 operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Later in June 2021, the LastConn malware, which has been discovered as part of activities attributed to the TA402 cluster, was assessed with high confidence to be an updated version of SharpStage.
Tools… “NimbleMamba, BrittleBush, LastConn, Micropsia”
2 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware discovered in TA402-attributed activity and assessed with high confidence to be an updated version of SharpStage.
LastConn is a previously used implant by TA402 (Molerats) for espionage and remote access, now likely replaced by NimbleMamba in recent campaigns.
A previously used TA402 implant that appears to have been replaced by NimbleMamba. It shared traits with NimbleMamba such as being written in C#, using base64 encoding in its C2 framework, and leveraging the Dropbox API for C2 communication.
Tools… “NimbleMamba, BrittleBush, LastConn, Micropsia”
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.