SUGARDUMP is a custom Windows credential-stealing malware associated with UNC3890 and used alongside SUGARUSH. It is designed primarily to harvest data from web browsers, including saved credentials from Firefox, Chrome, Opera, and Microsoft Edge, and to collect additional browser artifacts such as bookmarks and browsing history. The malware can also profile the victim environment by identifying installed browsers and their version information, supporting tailored follow-on activity.
Observed variants have relied on user execution through malicious Microsoft Excel spreadsheet attachments that required victims to enable macros. For persistence, SUGARDUMP has created Windows Scheduled Tasks using names intended to resemble legitimate browser crash-reporting components. It has also used masquerading by adopting names that imitate legitimate Mozilla crash-reporting software. Collected information has been staged locally before transmission and then exfiltrated to command-and-control infrastructure. At least one variant has used SMTP for command-and-control communications.
SUGARDUMP is best characterized as an infostealer focused on browser-resident data theft and host profiling on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The content repeatedly mentions malicious macros in Word/Excel documents, such as "enable macros," "embedded macros," and "macro-enabled documents."
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Multiple entries describe identifying files for theft or staging, such as "Confucius has used a file stealer that checks the Document, Downloads, Desktop, and Picture folders for documents and images with specific extensions" and "Peppy can identify specific files for exfiltration."
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that creates masqueraded scheduled tasks to execute its payload at user logon.
Malware variants executed through macro enablement in malicious XLS files.
Malware that collects browser bookmark and browsing history information.
Credential-stealing malware whose variants harvest credentials from multiple browsers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.