Skip to content
Malware family

SharpHound

SharpHound is an open-source Microsoft C#-based Active Directory reconnaissance and data-ingestion tool for BloodHound.

Profile source: Mallory opens in a new tab

SharpHound

Family profile

SharpHound is an open-source Microsoft C#-based Active Directory reconnaissance and data-ingestion tool for BloodHound. The content consistently describes it being used to collect and map Active Directory information, including users, groups, computers, sessions, shares, SPNs, service accounts, and domain relationships, often via LDAP and RPC-based enumeration. It is associated with discovery and reconnaissance activity and is referenced in detection content for command-line usage, file modifications, LDAP query patterns, anomalous SPN requests, and RPC-based user/session/share enumeration.

The tool appears in multiple intrusion contexts. Sophos reported attackers in the Chinese state-directed Operation Crimson Palace campaign, specifically Cluster Charlie, using SharpHound in November 2023 for Active Directory infrastructure mapping after deploying Havoc and Cobalt Strike, including in-memory execution through a Cobalt Strike beacon, DLL-based deployment, and lateral movement via WMIC and scheduled tasks. Cisco Talos reported the China-nexus actor UAT-8837 using SharpHound to collect Active Directory information after gaining access through vulnerable servers or compromised credentials, alongside tools such as EarthWorm, DWAgent, Impacket, Rubeus, GoExec, and Certipy, while targeting critical infrastructure sectors in North America. Additional reporting ties SharpHound to UNC3944 reconnaissance behavior and to Ryuk and BlackSuit intrusion activity for Active Directory discovery.

High-confidence behaviors directly mentioned in the content include in-memory loading without writing the tool to disk, deployment as a DLL, execution through Cobalt Strike, and use for enterprise network and Active Directory topology mapping. The content does not present SharpHound as self-propagating malware or ransomware; rather, it is repeatedly characterized as a legitimate/open-source reconnaissance utility frequently abused by threat actors during post-compromise discovery.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 20, 2026
Last activity
Jul 21, 2026
Feed role
C2 / Distribution
Host form
16 IP / 26 hostnames

Leading locations

  • CN15
  • DE5
  • US5
  • KR4
  • NL4
  • KG2
  • LU2
  • RU2
  • GB1
  • JP1
  • SG1

Leading providers

  • Hangzhou Alibaba Advertising Co.,Ltd.5
  • Shenzhen Tencent Computer Systems Company Limited5
  • CHINA UNICOM China169 Backbone4
  • SK Broadband Co Ltd3
  • FEMO IT SOLUTIONS LIMITED2
  • Ghosty Networks LLC2

Infrastructure traits

  • Hosting 31
  • Vpn 3
  • Anycast 1
  • Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

3 named in public reporting
Scattered Spider

UNC3944 will also use network reconnaissance tools like ADRecon, ADExplorer, and SharpHound.

Ryuk

"...most likely accomplished through the use of SharpHound, a Microsoft C#-based data 'injestor' tool for BloodHound..."

Exploited software

Vulnerabilities linked to SharpHound

1 CVEs

MITRE ATT&CK

SharpHound in ATT&CK

23 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.