Sibot

MITRE ATT&CK: S0589 View on attack.mitre.org

Aliases: Sibot

First seen
2021-01-01 00:00:00
Malware type
downloader, loader
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:58:50

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:gb country_code:ca

Context

Sibot is dual-purpose malware written in VBScript designed to achieve persistence on a compromised system as well as download and execute additional payloads. Microsoft discovered three Sibot variants in early 2021 during its investigation of APT29 and the SolarWinds Compromise.

Detection coverage

  • 422 Sigma rules

Malware & tools used

  • Query Registry (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • File Deletion (attack-pattern)
  • Web Service (attack-pattern)
  • Visual Basic (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Mshta (attack-pattern)
  • Rundll32 (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Indicator Removal (attack-pattern)
  • Fileless Storage (attack-pattern)
  • Modify Registry (attack-pattern)
  • Web Protocols (attack-pattern)

Used by threat actors

  • SolarWinds Compromise (campaign)
  • APT29 (threat-actor)

Reports & references

  • Microsoft — Goldmax Goldfinder Sibot Analyzing Nobelium Malware (report)
  • MITRE ATT&CK — S0589 (report)

External references