SDBot is a Windows-based IRC bot and remote access malware family that has been active since the early 2000s and has appeared in numerous variants. It functions as a backdoor and bot, allowing operators to execute commands on compromised systems, study victim networks, download or load additional malware, and disable security tooling in support of follow-on intrusion activity. SDBot has also been associated with criminal intrusion chains linked to TA505 and Clop operations, where it has been used during post-compromise staging alongside other remote access tools.
The malware supports multiple post-exploitation and operator-control functions. Reported capabilities include establishing persistence through Registry Run keys, decrypting and decompressing payloads to enable execution, executing commands through the Windows command shell, identifying the current user, determining domain and proxy configuration, deleting files, and using Remote Desktop Protocol to connect to victim machines. It has also been described as propagating by exploiting vulnerabilities and by copying itself to removable drives and network shares, reflecting worm-like spread in some variants.
Historically, SDBot has been tied to IRC-based command-and-control and was among the bot families adapted to exploit the Windows Plug and Play vulnerability addressed by MS05-039 during the 2005 Zotob-era outbreak. Variants were used to expand infections and provide a controllable backdoor on compromised hosts. Over time, the family has remained relevant less as a single uniform strain than as a broad lineage of IRC bot and RAT variants used for remote administration, malware delivery, reconnaissance, and preparation of victim environments for additional payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The SDBot RAT, which is used to study the network, load additional malware, and deactivate security solutions to prepare for the deployment of Clop
16 distinct techniques documented for this family, organized by ATT&CK tactic.
15th - The existing IRCbot is updated to use the MS05-039 exploit as an attack vector demonstrating a blended threat.
This malware uses application shimming for persistence and to avoid detection [T1546.011].
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
This malware uses application shimming for persistence and to avoid detection [T1546.011].
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT used in Clop campaigns for network study, loading additional malware, and disabling security solutions before ransomware deployment.
Malware used alongside phishing as part of the initial access stage in Clop infection chains.
Bot malware that decrypts and decompresses its payload for execution.
Bot/backdoor malware that persists by adding a Run key value when running with user privileges.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.