S0448: Rising Sun
Rising Sun is a modular backdoor that was used extensively in Operation Sharpshooter between 2017 and 2019. Rising Sun infected at least 87 organizations around the world, including nuclear, defense, energy, and financial service companies. Security researchers assessed Rising Sun included some source code from Lazarus Group's Trojan Duuzer.[1]
Security context for executives and security teams
S0448: Rising Sun describes [Rising Sun](https://attack.mitre.org/software/S0448) is a modular backdoor that was used extensively in [Operation Sharpshooter](https://attack.mitre.org/campaigns/C0013) between 2017 and 2019. [Rising Sun](https://attack.mitre.org/software/S0448) infected at least 87 organizations around the world, including nuclear, defense, energy, and financial service companies. Security researchers assessed [Rising Sun](https://attack.mitre.org/software/S0448) included some source code from [Lazarus Group](https://attack.mit...
Executive priority
S0448: Rising Sun is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate S0448: Rising Sun by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Windows), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
- Network, endpoint, and security-tool telemetry
Detection direction
- Validate whether S0448: Rising Sun appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Rising Sun
Rising Sun is a modular backdoor that was used extensively in Operation Sharpshooter between 2017 and 2019. Rising Sun infected at least 87 organizations around the world, including nuclear, defense, energy, and financial service companies. Security researchers assessed Rising Sun included some source code from Lazarus Group's Trojan Duuzer.[1]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1070.004 | File DeletionSub-technique | Rising Sun can delete files and artifacts it creates.[1] |
| Enterprise | T1005 | Data from Local System | Rising Sun has collected data and files from a compromised host.[1] |
| Enterprise | T1033 | System Owner/User Discovery | Rising Sun can detect the username of the infected host.[1] |
| Enterprise | T1560.003 | Archive via Custom MethodSub-technique | Rising Sun can archive data using RC4 encryption and Base64 encoding prior to exfiltration.[1] |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | Rising Sun has decrypted itself using a single-byte XOR scheme. Additionally, Rising Sun can decrypt its configuration data at runtime.[1] |
| Enterprise | T1082 | System Information Discovery | Rising Sun can detect the computer name and operating system.[1] |
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | Configuration data used by Rising Sun has been encrypted using an RC4 stream algorithm.[1] |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | Rising Sun has used HTTP and HTTPS for command and control.[1] |
| Enterprise | T1070 | Indicator Removal | Rising Sun can clear a memory blog in the process by overwriting it with junk bytes.[1] |
| Enterprise | T1057 | Process Discovery | Rising Sun can enumerate all running processes and process information on an infected machine.[1] |
| Enterprise | T1573.002 | Asymmetric CryptographySub-technique | Rising Sun variants can use SSL for encrypting C2 communications.CitationBleeping Computer Op Sharpshooter March 2019 |
| Enterprise | T1041 | Exfiltration Over C2 Channel | Rising Sun can send data gathered from the infected machine via HTTP POST request to the C2.[1] |
| Enterprise | T1016.001 | Internet Connection DiscoverySub-technique | Rising Sun can test a connection to a specified network IP address over a specified port number.[1] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | Rising Sun has executed commands using `cmd.exe /c “ > <%temp%>\AM. tmp” 2>&1`.[1] |
| Enterprise | T1083 | File and Directory Discovery | Rising Sun can enumerate information about files from the infected system, including file size, attributes, creation time, last access time, and write time. Rising Sun can enumerate the compilation timestamp of Windows executable files.[1] |
| Enterprise | T1012 | Query Registry | Rising Sun has identified the OS product name from a compromised host by searching the registry for `SOFTWARE\MICROSOFT\Windows NT\ CurrentVersion | ProductName`.[1] |
| Enterprise | T1106 | Native API | Rising Sun used dynamic API resolutions to various Windows APIs by leveraging `LoadLibrary()` and `GetProcAddress()`.[1] |
| Enterprise | T1564.001 | Hidden Files and DirectoriesSub-technique | Rising Sun can modify file attributes to hide files.[1] |
| Enterprise | T1680 | Local Storage Discovery | Rising Sun can detect drive information, including drive type, total number of bytes on disk, total number of free bytes on disk, and name of a specified volume.[1] |
| Enterprise | T1016 | System Network Configuration Discovery | Rising Sun can detect network adapter and IP address information.[1] |
Groups, software, and campaigns
C0013: Operation Sharpshooter
Operation Sharpshooter was a global cyber espionage campaign that targeted nuclear, defense, government, energy, and financial companies, with many located in Germany, Turkey, the United Kingdom, and the United States. Security researchers noted the campaign shared many similarities with previous Lazarus Group operations, including fake job recruitment lures and shared malware code.[1][2][3]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 2.1 | Current bundle | 1e1b9536b3ab… | ||
| 19.1 | 2.1 | Older bundle | 1e1b9536b3ab… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]McAfee Sharpshooter December 2018
Sherstobitoff, R., Malhotra, A., et. al.. (2018, December 18). Operation Sharpshooter Campaign Targets Global Defense, Critical Infrastructure. Retrieved May 14, 2020.
Open source URL - [2]mitre-attackS0448Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
