Skip to content

SAGE

Sage is a malware name used for at least two distinct threat contexts.

SAGE

Family profile

Sage is a malware name used for at least two distinct threat contexts. Most commonly, it refers to a Windows ransomware family, including Sage 2.0, that has been described as related to or a variant of CryLocker. In ransomware operations, Sage has been delivered through malicious spam campaigns using ZIP attachments that contain either macro-enabled Word documents or JavaScript downloaders, with some campaigns using double-zipped attachments. It has also been distributed by the financially motivated threat actor Storm-0324, which historically delivered Sage alongside other crimeware through phishing and exploit-kit-driven infection chains.

On infected Windows systems, Sage encrypts files, appends a dedicated extension, changes the desktop background to ransom instructions, and drops ransom notes both on the desktop and in directories containing encrypted data. Observed behavior includes repeated user account control prompts during execution, persistence via scheduled tasks, and storage of its executable in user profile locations. Post-infection communications have included HTTP callback traffic and, in some reporting, large-scale UDP traffic assessed as possible encoded or encrypted peer-to-peer communications. These characteristics support classification as ransomware with persistence and defense-evasion-related execution behavior.

Separately, Sage is also the name applied to a Java-based intrusion toolset used in Oracle E-Business Suite compromises associated with exploitation activity linked to the Cl0p extortion ecosystem and suspected FIN11-related operations. In that context, components including Sagegift, Sageleaf, and Sagewave have been used after exploitation to load in-memory payloads, install a malicious Java servlet filter, maintain access, and execute commands within compromised Oracle E-Business Suite environments. This Oracle-focused Sage toolchain is distinct in function and platform from the Windows ransomware family but shares the same naming convention in reporting. Because the supplied name is simply "sage," the term is ambiguous and encompasses both a Windows ransomware family and a Java post-exploitation framework used in Oracle E-Business Suite intrusions.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation

Samples

Recent samples

3 sandbox samples in the Derp library, newest 3 shown

Reported operators

Threat actors

1 named in public reporting
Storm-0324

Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... Sage ransomware

Reporting

Research mentioning SAGE