Truebot is a malware operation associated with opportunistic intrusion activity and downstream ransomware deployment. It has been linked to exploitation of CVE-2022-31199 in Netwrix Auditor and to follow-on activity culminating in Clop ransomware. Based on the available evidence, Truebot is best characterized as an initial-access and post-compromise intrusion enabler rather than a fully described standalone nation-state actor. Reported activity indicates use of vulnerability exploitation for initial access, followed by post-exploitation actions that support later-stage monetization by ransomware operators. Public reporting in the supplied facts directly connects Truebot to exploitation activity and an eventual Clop ransomware outcome, but does not provide high-confidence detail on broader targeting patterns, origin country, organizational structure, or additional aliases beyond the lowercase rendering of its name.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.