Sowbug is a threat actor tracked in the provided content as using Windows command shell activity, system information discovery, file and directory discovery, network share discovery, document collection, archiving, and masquerading. Observed behavior includes obtaining victim OS version and hardware configuration; using command-line activity during intrusions; identifying and extracting Word documents from servers using commands targeting *.doc and *.docx; searching for documents within a specific date range; attempting to identify installed software on victim systems; extracting documents from file servers; and bundling collected documents into RAR archives. The actor is also described as naming tools to masquerade as Windows or Adobe Reader software, including use of the filename adobecms.exe and the directory CSIDL_APPDATA\microsoft\security. ATT&CK technique references directly mentioned in the content include T1082 System Information Discovery, T1059.003 Windows Command Shell, T1135 Network Share Discovery, T1552 Unsecured Credentials, and T1003 OS Credential Dumping. No additional aliases, sub-groups, or nation-state attribution are directly supported by the provided content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor associated with the Network Share Discovery technique (T1135).
Listed as a threat actor associated with Windows Command Shell execution behavior relevant to this detection.
Referenced as a threat actor associated with credential access behavior, specifically techniques involving unsecured credentials and OS credential dumping in the context of LAPS password gathering via PowerShell.
Listed as a threat actor associated with WinPEAS-related post-exploitation/reconnaissance activity in the detection metadata.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.