SDBbot
MITRE ATT&CK: S0461 View on attack.mitre.org
Aliases: SDBbot, SDB bot
- First seen
- 2019-01-01 00:00:00
- Malware type
- backdoor, loader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 12 (9 malicious)
- Last IoC activity
- 2026-09-02 00:38:49
- Profile updated
- 2026-07-07 12:40:52
Targeted industries: financial-services retail-and-hospitality
Context
SDBbot is a backdoor with installer and loader components that has been used by TA505 since at least 2019.
Recent IoC activity
9 malicious indicators in Maltiverse are attributed to SDBbot (S0461). The 9 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | scanotec.dk | 2026-09-02 | 2 |
| URL | http://4u.fyi/7rLRv | 2026-04-18 | 1 |
| URL | http://4u.fyi/reHwS | 2026-04-18 | 1 |
| URL | http://4u.fyi/Sy7Pv | 2026-04-18 | 1 |
| URL | http://4u.fyi/tkGTS | 2026-04-18 | 1 |
| URL | http://4u.fyi/18YPQ | 2026-04-17 | 1 |
| URL | http://4u.fyi/llhrh | 2026-04-17 | 1 |
| URL | http://gmy.su/:wJ0db | 2026-03-20 | 1 |
| URL | http://gmy.su/:IJ0db | 2025-11-10 | 1 |
Detection coverage
- 1 YARA rules
- 455 Sigma rules
Malware & tools used
- File and Directory Discovery (attack-pattern)
- Indicator Removal (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Proxy (attack-pattern)
- Application Shimming (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Rundll32 (attack-pattern)
- Software Packing (attack-pattern)
- System Location Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Data from Local System (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Information Discovery (attack-pattern)
- Video Capture (attack-pattern)
- Image File Execution Options Injection (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Process Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- File Deletion (attack-pattern)
Used by threat actors
- TA505 (threat-actor)
Detection rules
- MALPEDIA_Win_Sdbbot_Auto (yara-rule)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- proofpoint.com — Ta505 Distributes New Sdbbot Remote Access Trojan Get2 Downloader (report)
- telekom.com — Cybersecurity Ta505 S Box Of Chocolate 597672 (report)
- telekom.com — Cybersecurity Ta505 Returns With A New Bag Of Tricks 602104 (report)
- secureworks.com — Gold Tahoe (report)
- telekom.com — Eager Beaver A Short Overview Of The Restless Threat Actor Ta505 609546 (report)
- blog.fox-it.com — Ta505 A Brief History Of Their Time (report)
- securityintelligence.com — Ta505 Continues To Infect Networks With Sdbbot Rat (report)
- web.archive.org — Ta505 Continues To Infect Networks With Sdbbot Rat (report)
- cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
- zdnet.com — The Malware That Usually Installs Ransomware And You Need To Remove Right Away (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 006 (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 009 (report)
- fsec.or.kr — 2297.Do (report)
- telekom.com — Inside Of Cl0P S Ransomware Operation 615824 (report)
- blog.intel471.com — A Brief History Of Ta505 (report)
- intel471.com — A Brief History Of Ta505 (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Sdbbot (report)
- vblocalhost.com — Vb2020 Jung (report)
- github.com — Sdbbot Unpacker (report)
- cyber.gov.au — Sdbbot Targeting Health Sector (report)
- global.ahnlab.com — Asec%20Report Vol.96 Eng (report)