Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomwareUsed by 1 actor

SAGE

Sage is a malware family name used in the provided reporting in two distinct but related contexts. Historically, Microsoft reported that the financially motivated initial-access broker Storm-0324 distributed Sage ransomware among a broader set of payloads since at least 2016, alongside malware such as Nymaim, Gozi, Trickbot, Gootkit, Dridex, GandCrab, and IcedID. More recent reporting uses “Sage” to describe a set of Java payloads deployed in Oracle E-Business Suite (EBS) intrusions associated with exploitation of CVE-2025-61882. In that EBS activity, attackers deployed multi-stage web shells related to the SAGE infection chain and used Java components including Sagegift, Sageleaf, and Sagewave. Sagegift is described as a payload that loads an in-memory dropper called Sageleaf, which installs a malicious Java servlet filter called Sagewave. Sagewave enabled attackers to deploy an AES-encrypted ZIP archive containing Java classes and to execute various commands in compromised EBS environments, supporting persistence and post-exploitation command execution. This Oracle EBS campaign began as early as July 2025, affected dozens of organizations, involved significant data exfiltration and extortion, and has been widely suspected to be linked to the Clop ransomware group, although formal attribution was not stated as confirmed. Talos also reported that after exploitation of CVE-2025-61882, threat actors deployed multi-stage web shells related to the SAGE infection chain. High-confidence associations in the content therefore include Storm-0324 as a historical distributor of Sage ransomware, and Oracle EBS exploitation activity in 2025 involving Sagegift/Sageleaf/Sagewave payloads, with command execution capability in compromised EBS environments.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Storm-0324

Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... Sage ransomware

via microsoft generalmicrosoft.com
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.