Sykipot
MITRE ATT&CK: S0018 View on attack.mitre.org
Aliases: Wkysol, getkys, Sykipot
- First seen
- 2007-01-01 00:00:00
- Malware type
- trojan
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:51:33
Targeted industries: defense-and-aerospace government-and-public-sector
Targeted regions: country_code:us
Context
Sykipot is malware that has been used in spearphishing campaigns since approximately 2007 against victims primarily in the US. One variant of Sykipot hijacks smart cards on victims. The group using this malware has also been referred to as Sykipot.
Detection coverage
- 1 YARA rules
- 106 Sigma rules
Malware & tools used
- System Service Discovery (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Multi-Factor Authentication Interception (attack-pattern)
- Domain Account (attack-pattern)
- Process Discovery (attack-pattern)
- Keylogging (attack-pattern)
- Remote System Discovery (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
Detection rules
- MALPEDIA_Win_Sykipot_Auto (yara-rule)
Reports & references
- secureworks.com — Bronze Edison (report)
- web.archive.org — Globalthreatintelreport (report)
- Trend Micro — Wp Detecting Apt Activity With Network Traffic Analysis (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Sykipot (report)
- Trend Micro — Sykipot Now Targeting Us Civil Aviation Sector Information (report)
- community.rsa.com — 185437 (report)
- Broadcom/Symantec — Sykipot Attacks (report)
- alienvault.com — Sykipot Is Back (report)
- alienvault.com — New Sykipot Developments (report)
- MITRE ATT&CK — S0018 (report)
- alienvault.com — Sykipot Variant Hijacks Dod And Windows Smart Cards (report)