Sykipot

MITRE ATT&CK: S0018 View on attack.mitre.org

Aliases: Wkysol, getkys, Sykipot

First seen
2007-01-01 00:00:00
Malware type
trojan
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:51:33

Targeted industries: defense-and-aerospace government-and-public-sector

Targeted regions: country_code:us

Context

Sykipot is malware that has been used in spearphishing campaigns since approximately 2007 against victims primarily in the US. One variant of Sykipot hijacks smart cards on victims. The group using this malware has also been referred to as Sykipot.

Detection coverage

  • 1 YARA rules
  • 106 Sigma rules

Malware & tools used

  • System Service Discovery (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Multi-Factor Authentication Interception (attack-pattern)
  • Domain Account (attack-pattern)
  • Process Discovery (attack-pattern)
  • Keylogging (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)

Detection rules

  • MALPEDIA_Win_Sykipot_Auto (yara-rule)

Reports & references

  • secureworks.com — Bronze Edison (report)
  • web.archive.org — Globalthreatintelreport (report)
  • Trend Micro — Wp Detecting Apt Activity With Network Traffic Analysis (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Sykipot (report)
  • Trend Micro — Sykipot Now Targeting Us Civil Aviation Sector Information (report)
  • community.rsa.com — 185437 (report)
  • Broadcom/Symantec — Sykipot Attacks (report)
  • alienvault.com — Sykipot Is Back (report)
  • alienvault.com — New Sykipot Developments (report)
  • MITRE ATT&CK — S0018 (report)
  • alienvault.com — Sykipot Variant Hijacks Dod And Windows Smart Cards (report)

External references