Sibot is a Windows malware implant associated with NOBELIUM, also tracked as APT29 or Cozy Bear, and was part of the tooling linked to the SolarWinds intrusion set alongside families such as SUNBURST, TEARDROP, GoldMax, and GoldFinder. It has been described as part of NOBELIUM’s layered persistence tradecraft.
Sibot is implemented as a script-based backdoor that executes commands using VBScript and can be launched through multiple Windows-native mechanisms, including mshta and scheduled tasks. It establishes persistence by modifying the Windows Registry to store a second-stage script, and it can also remove that registry-based persistence when instructed. Reported behavior includes querying the Registry for proxy configuration, checking whether the compromised host uses proxies, and using WMI to discover network connections and configuration details. Sibot has also used WMI process execution functionality to launch a malicious DLL.
The malware supports retrieval of encrypted tasking or payload data from command-and-control infrastructure, decrypting received data and writing it to disk. It has been observed downloading an additional DLL and disguising it as a driver file, indicating staged payload delivery and defense-evasion tradecraft. Sibot also includes cleanup logic: it can delete itself and remove associated Registry artifacts in response to specific server instructions.
Available reporting ties Sibot to post-compromise persistence and remote command execution on Windows systems rather than broad commodity distribution. Its known use is aligned with targeted espionage operations conducted by NOBELIUM against high-value organizations, especially in government and related sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
APT29 has been observed gaining persistence via backdoor and web shell malware variants, manipulating and adding accounts to compromised networks, conducting password spraying attacks to gain access to additional accounts, scheduled tasks, adding Registry Run keys, hijacking legitimate application-specific startup scripts to run malware on system startup, and WMI event subscriptions.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
APT29 has been observed gaining persistence via backdoor and web shell malware variants, manipulating and adding accounts to compromised networks, conducting password spraying attacks to gain access to additional accounts, scheduled tasks, adding Registry Run keys, hijacking legitimate application-specific startup scripts to run malware on system startup, and WMI event subscriptions.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
APT29 has been observed gaining persistence via backdoor and web shell malware variants, manipulating and adding accounts to compromised networks, conducting password spraying attacks to gain access to additional accounts, scheduled tasks, adding Registry Run keys, hijacking legitimate application-specific startup scripts to run malware on system startup, and WMI event subscriptions.
APT29 has been observed gaining persistence via backdoor and web shell malware variants, manipulating and adding accounts to compromised networks, conducting password spraying attacks to gain access to additional accounts, scheduled tasks, adding Registry Run keys, hijacking legitimate application-specific startup scripts to run malware on system startup, and WMI event subscriptions.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
APT29 has been observed gaining persistence via backdoor and web shell malware variants, manipulating and adding accounts to compromised networks, conducting password spraying attacks to gain access to additional accounts, scheduled tasks, adding Registry Run keys, hijacking legitimate application-specific startup scripts to run malware on system startup, and WMI event subscriptions.
"Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "ADVSTORESHELL... strings... encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed." / "APT29 has used encoded PowerShell commands." / "APT41 used VMProtected binaries..."
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
APT5 has used the THINBLOOD utility to clear SSL VPN log files located at /home/runtime/logs.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
CSPY Downloader has the ability to remove values it writes to the Registry.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
APT29 has use mshta to execute malicious scripts on a compromised host... APT32 has used mshta.exe for code execution... APT38 has used a renamed version of mshta.exe to execute malicious HTML files... FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Their toolkit includes ... SharpView, Sibot, SoreFang, SUNBURST...
Executes commands using VBScript.
Checks whether compromised systems are configured to use proxies.
APT29 malware written in Visual Basic and used in the SolarWinds compromise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.