SharpShooter is a malware delivery framework and first-stage downloader used to execute follow-on payloads on Windows systems. It has been distributed through malicious email attachments, including weaponized Microsoft Office documents and PDF files, relying on user interaction to open the lure document and trigger execution. The framework’s first-stage component dynamically resolves Windows APIs such as LoadLibraryA and GetProcAddress and uses process-creation functionality including CreateProcessA, indicating a staged execution model designed to launch additional code or payloads while reducing static detection opportunities. SharpShooter is primarily associated with phishing and spearphishing-style delivery and is best characterized as a Windows-focused loader/downloader used for initial compromise and payload execution rather than as a standalone final-stage implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan delivered through malicious email attachments.
Downloader that dynamically resolves Windows libraries/APIs and can create processes (CreateProcessA).
Sharpshooter has sent malicious DOC and PDF files to targets so that they can be opened by a user.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.