Skip to main content
Mallory
MalwareRansomwareUsed by 5 actorsExploits 4 CVEs

TrueBot

TrueBot is a malware family used as a first-stage downloader and command-and-control malware. The provided content states it can collect system information and take screenshots, and has been used to download additional payloads including FlawedGrace and Cobalt Strike Beacon. It is associated with TA505/FIN11, also tracked as GOLD TAHOE and linked in the reporting to Clop operations; Microsoft also linked TrueBot deployment in PaperCut intrusions to the Clop-associated actor Lace Tempest. Since late 2018, TA505/GOLD TAHOE has distributed TrueBot alongside other malware such as Get2, SDBbot, GraceWire, and FlawedAmmy to facilitate follow-on intrusion activity including lateral movement. The content also links TrueBot to exploitation chains involving public-facing enterprise software: FBI/CISA reporting identified download and execution of TrueBot during exploitation of PaperCut MF/NG CVE-2023-27350, and Cisco Talos linked CVE-2022-31199 in Netwrix Auditor to TrueBot activity that eventually led to Clop ransomware. Reporting in the content further states that after attackers gained access to vulnerable servers, they deployed TrueBot, and that TrueBot activity has been observed infecting networks in the United States and Canada. Mentioned indicators include a file identified as TrueBot named ld.txt with SHA-256 c0f8aeeb2d11c6e751ee87c40ee609aceb1c1036706a5af0d3d78738b6cc4125. The content also notes traces of TrueBot in infrastructure discussed alongside ShadowSyndicate and multiple ransomware families, but cautions that subnet overlap alone is not definitive attribution.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

4 CVES
CVE-2023-27350Unauthenticated Authentication Bypass and RCE in PaperCut MF/NGExploited in the wild

The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory (CSA) in response to the active exploitation of CVE-2023-27350. This vulnerability occurs in certain versions of PaperCut NG and PaperCut MF and enables an unauthenticated actor to execute malicious code remotely without credentials. | The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons, although it is unclear at which stage in the attack these tools were executed.

via cisacisa.gov
CVE-2023-0669Pre-authentication RCE in Fortra GoAnywhere MFT License Response ServletExploited in the wild

In late January 2023, the CL0P ransomware group launched a campaign using a zero-day vulnerability, now catalogued as CVE-2023-0669, to target the GoAnywhere MFT platform.

via cisa advisoriescisa.gov
CVE-2022-31199Netwrix Auditor User Activity Video Recording Remote Code ExecutionExploited in the wild

CVE-2022-31199 Cisco Talos was able to link CVE-2022-31199, a vulnerability in Netwrix Auditor, to Truebot activity (and eventually Clop ransomware)... To our knowledge, there is no public exploit for this vulnerability. | “Cisco Talos was able to link CVE-2022-31199... to Truebot activity (and eventually Clop ransomware)”

via vulncheck blogvulncheck.com
CVE-2023-27351Authentication Bypass in PaperCut NG/MF SecurityRequestFilterExploited in the wild

Once they gained access to the server, they deployed the TrueBot malware, which has also been previously linked to the Clop ransomware operation.

via bleeping computerbleepingcomputer.com
THREAT ACTORS

Groups observed using it

5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Bl00dy Ransomware Gang

The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons, although it is unclear at which stage in the attack these tools were executed.

via cisacisa.gov
TA505

Truebot is a first-stage downloader module that can collect system information and take screenshots... In the case of TA505, Truebot has been used to download FlawedGrace or Cobalt Strike beacons.

via cisa advisoriescisa.gov
Silence

Truebot is a first-stage downloader module that can collect system information and take screenshots... In the case of TA505, Truebot has been used to download FlawedGrace or Cobalt Strike beacons.

via cisa advisoriescisa.gov
FIN11

Once they gained access to the server, they deployed the TrueBot malware, which has also been previously linked to the Clop ransomware operation.

via bleeping computerbleepingcomputer.com
Lace Tempest

Once they gained access to the server, they deployed the TrueBot malware, which has also been previously linked to the Clop ransomware operation.

via bleeping computerbleepingcomputer.com
MITRE ATT&CK

Techniques & procedures

9 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence2

CVE-2023-27350 allows a remote actor to bypass authentication and conduct remote code execution on the affected installations of PaperCut... malicious actors exploited CVE-2023-27350 beginning in mid-April 2023.

Execution

1 technique
T1129Shared ModulesEvidence1
TacticExecution

After connecting to the C2 infrastructure, Truebot can be instructed to load shell code or DLLs, download additional modules [T1129], run them, or delete itself.

T1055Process InjectionEvidence1

After connecting to the C2 infrastructure, Truebot can be instructed to load shell code [T1055] or DLLs.

Stealth

2 techniques
T1055Process InjectionEvidence1

After connecting to the C2 infrastructure, Truebot can be instructed to load shell code [T1055] or DLLs.

T1070Indicator RemovalEvidence1
TacticStealth

After connecting to the C2 infrastructure, Truebot can be instructed to load shell code or DLLs, download additional modules, run them, or delete itself [T1070].

T1553.002Code SigningEvidence1

Silence has used a valid certificate to sign their primary loader Silence.Downloader (aka TrueBot).

Collection

1 technique
T1113Screen CaptureEvidence1

Truebot is a first-stage downloader module that can collect system information and take screenshots [T1113].

T1071Application Layer ProtocolEvidence1

The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons... Associated with TrueBot C2... Associated with Cobalt Strike Beacon.

T1071.001Web ProtocolsEvidence1

"Ultimately, Microsoft says a Cobalt Strike beacon was deployed..."

T1105Ingress Tool TransferEvidence3

Legitimate remote management and maintenance (RMM) software was downloaded and executed on victim systems via commands issued through PaperCut’s print scripting interface... The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons.

INDICATORS OF COMPROMISE

IOCs tracked for this family

45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
34 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
7 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
4 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app2 months ago
ip.v4●●●●●●●●●●●●View more in app7 months ago
ip.v4●●●●●●●●●●●●View more in app7 months ago
ip.v4●●●●●●●●●●●●View more in app7 months ago
ip.v4●●●●●●●●●●●●View more in app7 months ago
ip.v4●●●●●●●●●●●●View more in app7 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching45

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution5

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities4

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping9

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.