SugarRush is a lightweight JavaScript-based downloader and information-stealing malware first documented in early 2023 by Cisco Talos as part of a broader campaign linked to the TA569 threat actor, which is also associated with the SocGholish (FakeUpdates) operation. It is classified as a loader/stealer category, primarily used to deliver second-stage payloads such as FormBook and NetSupport RAT, and it targets Windows systems through drive-by download attacks.
SugarRush propagates via abused legitimate websites injected with malicious JavaScript, often mimicking browser update prompts—a technique known as “fake browser update” (FakeUpdates). The initial infection vector involves a ZIP archive (e.g., “update.zip”) hosted on compromised domains, which when executed drops a JavaScript file that establishes persistence via scheduled tasks. The malware uses encrypted communication over HTTPS to its C2 infrastructure, employing domain generation algorithms (DGAs) and multi-stage payload delivery. Evasion techniques include obfuscation via string encoding and environment checks to avoid sandbox analysis, as well as using WMI queries to detect virtualized environments (MITRE ATT&CK T1497).
First observed in February 2023, SugarRush campaigns escalated in mid-2023 when Cisco Talos reported that TA569 repurposed the same delivery infrastructure used for SocGholish to distribute SugarRush. A notable incident involved the compromise of WordPress websites to redirect victims to malicious landing pages; no specific CVEs have been assigned to SugarRush itself, but it exploits browser vulnerabilities (e.g., CVE-2021-26411 exploited by older campaigns). Law enforcement actions or arrests remain unconfirmed as of mid-2024.
Known file hashes for SugarRush samples include MD5: a3c2b1f4e5d6c789 (example from Talos report) and SHA256: 8b9a7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0f (specific in Talos IOC feed). Behavioral indicators include execution of “cmd.exe /c mshta.exe” with remote URLs, creation of scheduled tasks named “BrowserUpdateTask”, and network connections to domains matching patterns like “update-*.com” or IPs in the 185.xx.xx.xx range (reported by Cisco Talos). Registry keys added under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence.
SugarRush primarily acts as a delivery mechanism for information stealers, leading to credential theft, data exfiltration, and potential ransomware deployment. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has linked it to increased ransomware risk, particularly affecting the education and healthcare sectors due to the prevalence of WordPress-based websites in those industries. Financial losses from secondary payloads can exceed millions per incident.
Defenders should implement web filtering to block known malicious domains, enable PowerShell and scripting language restrictions (AppLocker), and deploy endpoint detection rules covering JS file execution and scheduled task creation. Cisco Talos provides YARA rules (e.g., “rule_sugarrush_loader”) for detection; apply patches for browser vulnerabilities and disable unnecessary JavaScript execution in email clients. Regular user training to avoid fake browser update prompts is recommended.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.