SUGARUSH is malware used by UNC3890 in campaign C0010. The provided content identifies it as unique/custom malware used alongside SUGARDUMP. Observed behavior includes creating a Windows service named "Service1" for persistence, checking for internet connectivity from an infected host before attempting to establish a new TCP connection, and using TCP for command-and-control communications, including over TCP port 4585. The content also references versions v1.0 to v1.1. Campaign context in the source material states UNC3890 likely operated a watering-hole on the login page of a legitimate Israeli shipping company, used lookalike domains impersonating services such as LinkedIn, Facebook, Office 365, and Pfizer, and downloaded or staged malware and tools for direct delivery onto compromised systems. High-confidence indicators and artifacts directly mentioned in the content include the service name "Service1" and C2 port 4585/TCP.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... SUGARUSH ... (v1.0→v1.1) ...
SUGARUSH (v1.0→v1.1)
Malware that verifies internet connectivity before creating a new TCP connection.
Malware that creates a Windows service named Service1 for persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.