Sowbug

G0054

Threat group.View on attack.mitre.org

About this group

Sowbug is a threat group that has conducted targeted attacks against organizations in South America and Southeast Asia, particularly government entities, since at least 2015.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1003
OS Credential Dumping

Sowbug has used credential dumping tools.

T1036.005
Match Legitimate Resource Name or Location

Sowbug named its tools to masquerade as Windows or Adobe Reader software, such as by using the file name adobecms.exe and the directory CSIDL_APPDATA\microsoft\security.

T1039
Data from Network Shared Drive

Sowbug extracted Word documents from a file server on a victim network.

T1056.001
Keylogging

Sowbug has used keylogging tools.

T1059.003
Windows Command Shell

Sowbug has used command line during its intrusions.

T1082
System Information Discovery

Sowbug obtained OS version and hardware configuration from a victim.

T1083
File and Directory Discovery

Sowbug identified and extracted all Word documents on a server by using a command containing * .doc and *.docx. The actors also searched for documents based on a specific date range and attempted to identify all installed software on a victim.

T1135
Network Share Discovery

Sowbug listed remote shared drives that were accessible from a victim.

T1560.001
Archive via Utility

Sowbug extracted documents and bundled them into a RAR archive.

Software2

Campaigns0

None recorded.

References1

  1. Symantec Sowbug Nov 2017 Open source
    Symantec Security Response. (2017, November 7). Sowbug: Cyber espionage group targets South American and Southeast Asian governments. Retrieved November 16, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.