SOUNDBITE

MITRE ATT&CK: S0157 View on attack.mitre.org

Aliases: denis, SOUNDBITE

First seen
2018-02-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:45:15

Targeted industries: government-and-public-sector technology-and-telecommunications media-and-entertainment

Targeted regions: country_code:vn country_code:us

Context

SOUNDBITE is a signature backdoor associated with APT32, primarily used for cyber-espionage campaigns targeting government and telecommunications sectors.

Detection coverage

  • 1 YARA rules
  • 142 Sigma rules

Malware & tools used

  • System Information Discovery (attack-pattern)
  • Modify Registry (attack-pattern)
  • DNS (attack-pattern)
  • Application Window Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Soundbite_Auto (yara-rule)

Reports & references

  • Mandiant — Cyber Espionage Apt32 (report)
  • secureworks.com — Tin Woodlawn (report)
  • picussecurity.com — Picus 10 Critical Mitre Attck Techniques T1055 Process Injection (report)
  • mp.weixin.qq.com — Xpsexp2J5Ie7Wnsmevc24A (report)
  • go.recordedfuture.com — Cta 2020 1110 (report)
  • ruxcon.org.au — Bart Ruxcon Presentation.Pptx (report)
  • blog.viettelcybersecurity.com — Apt32 Deobfuscation Arsenal Deobfuscating Mot Vai Loai Obfucation Toolkit Cua Apt32 Phan 1 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Soundbite (report)
  • Kaspersky — 78203 (report)
  • MITRE ATT&CK — S0157 (report)
  • MITRE ATT&CK — S0157 (report)

External references