SDBbot

MITRE ATT&CK: S0461 View on attack.mitre.org

Aliases: SDBbot, SDB bot

First seen
2019-01-01 00:00:00
Malware type
backdoor, loader
Family
Malware family
Operating systems
windows
Related IoCs
12 (9 malicious)
Last IoC activity
2026-09-02 00:38:49
Profile updated
2026-07-07 12:40:52

Targeted industries: financial-services retail-and-hospitality

Context

SDBbot is a backdoor with installer and loader components that has been used by TA505 since at least 2019.

Recent IoC activity

9 malicious indicators in Maltiverse are attributed to SDBbot (S0461). The 9 most recently updated:

TypeIndicatorUpdatedSources
hostname scanotec.dk 2026-09-02 2
URL http://4u.fyi/7rLRv 2026-04-18 1
URL http://4u.fyi/reHwS 2026-04-18 1
URL http://4u.fyi/Sy7Pv 2026-04-18 1
URL http://4u.fyi/tkGTS 2026-04-18 1
URL http://4u.fyi/18YPQ 2026-04-17 1
URL http://4u.fyi/llhrh 2026-04-17 1
URL http://gmy.su/:wJ0db 2026-03-20 1
URL http://gmy.su/:IJ0db 2025-11-10 1

Detection coverage

  • 1 YARA rules
  • 455 Sigma rules

Malware & tools used

  • File and Directory Discovery (attack-pattern)
  • Indicator Removal (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Proxy (attack-pattern)
  • Application Shimming (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Rundll32 (attack-pattern)
  • Software Packing (attack-pattern)
  • System Location Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Data from Local System (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Video Capture (attack-pattern)
  • Image File Execution Options Injection (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Process Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • File Deletion (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Sdbbot_Auto (yara-rule)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • proofpoint.com — Ta505 Distributes New Sdbbot Remote Access Trojan Get2 Downloader (report)
  • telekom.com — Cybersecurity Ta505 S Box Of Chocolate 597672 (report)
  • telekom.com — Cybersecurity Ta505 Returns With A New Bag Of Tricks 602104 (report)
  • secureworks.com — Gold Tahoe (report)
  • telekom.com — Eager Beaver A Short Overview Of The Restless Threat Actor Ta505 609546 (report)
  • blog.fox-it.com — Ta505 A Brief History Of Their Time (report)
  • securityintelligence.com — Ta505 Continues To Infect Networks With Sdbbot Rat (report)
  • web.archive.org — Ta505 Continues To Infect Networks With Sdbbot Rat (report)
  • cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
  • zdnet.com — The Malware That Usually Installs Ransomware And You Need To Remove Right Away (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 006 (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 009 (report)
  • fsec.or.kr — 2297.Do (report)
  • telekom.com — Inside Of Cl0P S Ransomware Operation 615824 (report)
  • blog.intel471.com — A Brief History Of Ta505 (report)
  • intel471.com — A Brief History Of Ta505 (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Sdbbot (report)
  • vblocalhost.com — Vb2020 Jung (report)
  • github.com — Sdbbot Unpacker (report)
  • cyber.gov.au — Sdbbot Targeting Health Sector (report)
  • global.ahnlab.com — Asec%20Report Vol.96 Eng (report)

External references