Campaign · all campaigns
Operation SharpshooterC0013 unknown
aka Operation Sharpshooter
Last updated: 2026-07-03
About this actor
[Operation Sharpshooter](https://attack.mitre.org/campaigns/C0013) was a global cyber espionage campaign that targeted nuclear, defense, government, energy, and financial companies, with many located in Germany, Turkey, the United Kingdom, and the United States. Security researchers noted the campaign shared many similarities with previous [Lazarus Group](https://attack.mitre.org/groups/G0032) operations, including fake job recruitment lures and shared malware code.(Citation: McAfee Sharpshooter December 2018)(Citation: Bleeping Computer Op Sharpshooter March 2019)(Citation: Threatpost New Op Sharpshooter Data March 2019)
Source: MITRE ATT&CK
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
CM-6 | 12 / 22 | 55% |
SI-3 | 12 / 22 | 55% |
SI-4 | 12 / 22 | 55% |
CM-2 | 11 / 22 | 50% |
CM-7 | 11 / 22 | 50% |
AC-6 | 8 / 22 | 36% |
CA-7 | 8 / 22 | 36% |
AC-3 | 7 / 22 | 32% |
SC-7 | 7 / 22 | 32% |
SI-10 | 7 / 22 | 32% |
SI-2 | 7 / 22 | 32% |
AC-2 | 6 / 22 | 27% |
AC-4 | 6 / 22 | 27% |
SI-7 | 6 / 22 | 27% |
SC-18 | 5 / 22 | 23% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- SideCopy 0.31
- LazyScripter 0.30
- C0011 0.29
- TA2541 0.28
- Gorgon Group 0.25