SAGE
Sage is a malware family name used in the provided reporting in two distinct but related contexts. Historically, Microsoft reported that the financially motivated initial-access broker Storm-0324 distributed Sage ransomware among a broader set of payloads since at least 2016, alongside malware such as Nymaim, Gozi, Trickbot, Gootkit, Dridex, GandCrab, and IcedID. More recent reporting uses “Sage” to describe a set of Java payloads deployed in Oracle E-Business Suite (EBS) intrusions associated with exploitation of CVE-2025-61882. In that EBS activity, attackers deployed multi-stage web shells related to the SAGE infection chain and used Java components including Sagegift, Sageleaf, and Sagewave. Sagegift is described as a payload that loads an in-memory dropper called Sageleaf, which installs a malicious Java servlet filter called Sagewave. Sagewave enabled attackers to deploy an AES-encrypted ZIP archive containing Java classes and to execute various commands in compromised EBS environments, supporting persistence and post-exploitation command execution. This Oracle EBS campaign began as early as July 2025, affected dozens of organizations, involved significant data exfiltration and extortion, and has been widely suspected to be linked to the Clop ransomware group, although formal attribution was not stated as confirmed. Talos also reported that after exploitation of CVE-2025-61882, threat actors deployed multi-stage web shells related to the SAGE infection chain. High-confidence associations in the content therefore include Storm-0324 as a historical distributor of Sage ransomware, and Oracle EBS exploitation activity in 2025 involving Sagegift/Sageleaf/Sagewave payloads, with command execution capability in compromised EBS environments.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... Sage ransomware
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-stage web shell infection chain used post-exploitation to maintain access; details of capabilities beyond web shelling are not provided here.
Sage is a set of Java-based payloads used in Oracle EBS attacks, including Sagegift (loader), Sageleaf (in-memory dropper), and Sagewave (malicious servlet filter). These components enable attackers to execute commands and deploy additional malicious code within the compromised environment.
Sage is a set of Java-based payloads used in Oracle EBS attacks, including Sagegift (loader), Sageleaf (in-memory dropper), and Sagewave (malicious servlet filter). These components enable attackers to execute commands and deploy additional malicious code within compromised environments.
A ransomware family historically distributed by Storm-0324.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.