Skip to content

Malware

SharpStage

aka LastConn

The SharpStage backdoor is a .NET malware with backdoor capabilities.

The SharpStage backdoor is a .NET malware with backdoor capabilities. Its name is a derivative of the main activity class called “Stage_One”. SharpStage can take screenshots, run arbitrary commands and downloads additional payloads. It exfiltrates data from the infected machine to a dropbox account by implementing a dropbox client in its code. SharpStage was seen used by the Molerats group in targeted attacks in the middle east.


Family metadata imported from Malpedia (Fraunhofer FKIE).