Netskope Threat Labs

SUGARDUMP

ATP Sandbox Adv. Heuristics

SUGARDUMP is a proprietary browser credential harvesting tool that UNC3890 used during its campaign against Israeli targets. Multiple versions evolved over time, adding SMTP and HTTP command and control channels between early 2021 and April 2022.

First seen
October 2022
Last seen
October 2026

13 techniques across 7 tactics.

TA0002 Execution

TA0005 Stealth

TA0006 Credential Access

  • T1555Credentials from Password Stores

TA0007 Discovery

  • T1083File and Directory Discovery
  • T1217Browser Information Discovery
  • T1518Software Discovery

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel
Alert Name
ByteCode-MSIL.Backdoor.Sugardump
ByteCode-MSIL.Trojan.Sugardump
Document-Excel.Trojan.Sugardump
Win32.Backdoor.Sugardump
Win32.Trojan.Sugardump