Sardonic

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[Sardonic](https://attack.mitre.org/software/S1085) is a backdoor written in C and C++ that is known to be used by [FIN8](https://attack.mitre.org/groups/G0061), as early as August 2021 to target a financial institution in the United States. [Sardonic](https://attack.mitre.org/software/S1085) has a plugin system that can load specially made DLLs and execute their functions.(Citation: Bitdefender Sardonic Aug 2021)(Citation: Symantec FIN8 Jul 2023)

Associated Techniques (25)
ID ATT&CK Tactics
T1005 Data from Local System -
T1007 System Service Discovery -
T1016 System Network Configuration Discovery -
T1027 Obfuscated Files or Information -
T1027.010 Command Obfuscation -
T1047 Windows Management Instrumentation -
T1049 System Network Connections Discovery -
T1055.004 Asynchronous Procedure Call -
T1057 Process Discovery -
T1059.001 PowerShell -
T1059.003 Windows Command Shell -
T1070 Indicator Removal -
T1082 System Information Discovery -
T1095 Non-Application Layer Protocol -
T1105 Ingress Tool Transfer -
Used by Actors (1)
Metadata
ID: 47
Created: 13/01/2026 17:48
Updated: 06/03/2026 04:00