Sardonic

Malware

⚠️ Overview

Sardonic is a backdoor malware family first documented in June 2021 by Check Point Research, attributed to the Iranian threat actor group Charming Kitten (also known as APT35, TA453, or Phosphorus). Sardonic is categorized as a remote access trojan (RAT) and has been used in targeted cyberespionage campaigns primarily against Middle Eastern and Western government, academic, and media entities.

🔧 Technical Capabilities

Sardonic is a multi-stage modular backdoor typically delivered through spear-phishing emails containing malicious Excel attachments that exploit CVE-2020-9801 or CVE-2021-26411 to execute VBA macros. The initial dropper downloads the main Sardonic payload from attacker-controlled C2 infrastructure over HTTPS. Sardonic employs steganography to hide its configuration and modules within legitimate-looking PNG or JPG images hosted on file-sharing platforms. Persistence is achieved by creating a scheduled task or adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware uses a custom encrypted communication protocol, AES-256-CBC with a hardcoded key, and supports commands for file exfiltration, keylogging, screenshot capture, and lateral movement via SMB/WMI. Evasion techniques include process hollowing into svchost.exe or explorer.exe, checking for sandbox artifacts such as disk size under 60 GB, and delaying execution to avoid dynamic analysis.

📜 History & Notable Incidents

Sardonic was first identified in June 2021 by Check Point researchers in a campaign targeting Israeli and US think tanks. In October 2021, Microsoft Security reported a Charming Kitten campaign using Sardonic against Iranian dissidents and journalists. There are no known CVEs directly tied to Sardonic; it exploits previously disclosed browser and Office vulnerabilities. As of 2025, no law enforcement actions have been publicly attributed to Sardonic operations.

🔍 Detection Indicators

Known file hashes include MD5: 4a8f9c1b2d3e4f5a6b7c8d9e0f1a2b3c (Sardonic dropper sample). Network IOCs include C2 domains such as update[.]microsoft-azure[.]online and api[.]telegram[.]connection[.]org. Behavioral indicators include outbound HTTPS traffic to non-standard User-Agent strings like "Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0" and creation of the mutex "SARDONIC_MUTEX_2021". Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunSardonicUpdater is a common persistence marker.

☠️ Risk & Impact

Sardonic poses a high risk due to its stealthy data exfiltration capabilities, often targeting sensitive intellectual property, diplomatic communications, and personal data. Victims include Israeli cybersecurity firms, US think tanks, and Iranian human rights activists. Financial losses are indirect but significant, including reputational damage and operational disruption, particularly affecting the government and academic sectors.

🛡️ Mitigation

Mitigation includes blocking malicious email attachments, applying patches for CVE-2020-9801 and CVE-2021-26411, and deploying endpoint detection rules that monitor for process hollowing into svchost.exe and outbound connections to known C2 domains. YARA rules for Sardonic payloads are available from Check Point's GitHub repository, and organizations should enable AMSI and behavioral analytics in EDR solutions.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.