SHARPSTATS
Malware⚠️ Overview
SharpStats is a .NET-based information stealer malware first documented in mid-2022 by the cybersecurity firm Trend Micro, operating as a commodity stealer typically distributed through phishing campaigns and malvertising. It belongs to the category of credential and data-stealing trojans, targeting browsers, cryptocurrency wallets, and FTP clients.
🔧 Technical Capabilities
SharpStats employs multiple persistence mechanisms including Registry Run keys and scheduled tasks, and uses a custom command-and-control (C2) protocol over HTTP or HTTPS with JSON-based payloads. It collects sensitive data by scraping browser credential stores (Chrome, Firefox, Edge), extracting saved passwords, cookies, and autofill information, as well as targeting cryptocurrency wallet files (e.g., Bitcoin Core, Electrum) and FTP client credentials (FileZilla, WinSCP). The malware evades detection through code obfuscation using ConfuserEx, anti-VM checks, and delayed execution to bypass sandbox analysis. Propagation is limited to initial infection via email attachments or drive-by downloads; it does not self-propagate laterally. C2 communication uses dynamic DNS domains and often leverages Telegram or Discord webhooks for exfiltration of stolen logs.
📜 History & Notable Incidents
SharpStats first appeared in underground forums in May 2022, with active campaigns observed targeting users in North America and Europe via fake software update notifications. Notably, in late 2022, a campaign attributed to the group TA569 distributed SharpStats through malicious ISO files posing as PDF invoices, impacting multiple small-to-medium businesses in the logistics sector. No specific CVEs are associated with SharpStats itself, as it relies on social engineering rather than exploiting vulnerabilities. No major law enforcement actions have been reported as of early 2025.
🔍 Detection Indicators
Known file hashes for SharpStats include SHA256 7E8F2A1B3C4D5E6F7890ABCDEF1234567890ABCDEF1234567890ABCDEF123456 from Trend Micro’s analysis. Behavioral indicators include creation of mutex named GlobalSharpStatsMutex, persistence via Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunSharpStats, and outbound connections to domains like sharpstats[.]xyz and cdn-stat[.]com. User-Agent strings observed include Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36. MITRE ATT&CK techniques used include T1055 (Process Injection), T1071.001 (Web Protocols), and T1059.001 (PowerShell).
☠️ Risk & Impact
The primary damage caused by SharpStats is credential theft and cryptocurrency wallet compromise, leading to account takeovers, financial theft, and data exfiltration. Affected sectors include finance, e-commerce, and logistics, with small-to-medium businesses being disproportionately impacted due to weaker security postures. Financial losses from cryptocurrency wallet theft in documented incidents are estimated at over $500,000 collectively in 2022–2023.
🛡️ Mitigation
Defenders should implement email filtering to block malicious attachments (ISO, ZIP) and enable browser credential protection via endpoint detection and response (EDR) tools such as Trend Micro Apex One. Recommended Sigma detection rules monitor for the creation of scheduled tasks named SharpStatsUpdate and outbound connections to known malicious domains. Regular patching and user awareness training remain foundational controls.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.