Netskope Threat Labs

SUGARUSH

ATP Sandbox Adv. Heuristics

SUGARUSH is a small custom backdoor that establishes a reverse shell over TCP to a hard-coded command and control address. Mandiant identified it during analysis of the UNC3890 campaign against Israeli companies that began in late 2020.

First seen
October 2022
Last seen
October 2026

6 techniques across 4 tactics.

TA0002 Execution

TA0003 Persistence

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1680Local Storage Discovery

TA0011 Command and Control

  • T1095Non-Application Layer Protocol
  • T1571Non-Standard Port
Alert Name
ByteCode-MSIL.Backdoor.Sugarush