Skip to content

Malware

SharpStage

aka LastConn

The SharpStage backdoor is a .NET malware with backdoor capabilities.

SharpStage, also known as LastConn, is a Windows malware family operated by Molerats.

Background

SharpStage is .NET malware equipped with backdoor functionality. Its name comes from its primary activity class, “Stage_One”. The backdoor can grab screenshots, execute arbitrary commands, and pull down further payloads. It siphons data off the compromised host to a dropbox account using a built-in dropbox client. The Molerats group has been observed deploying SharpStage in targeted operations across the Middle East.


Source: Malpedia (Fraunhofer FKIE).