Sibot

S0589

Malware.View on attack.mitre.org

About this malware

Sibot is dual-purpose malware written in VBScript designed to achieve persistence on a compromised system as well as download and execute additional payloads. Microsoft discovered three Sibot variants in early 2021 during its investigation of APT29 and the SolarWinds Compromise.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1012
Query Registry

Sibot has queried the registry for proxy server information.

T1016
System Network Configuration Discovery

Sibot checked if the compromised system is configured to use proxies.

T1027.010
Command Obfuscation

Sibot has obfuscated scripts used in execution.

T1027.011
Fileless Storage

Sibot has installed a second-stage script in the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\sibot registry key.

T1036.005
Match Legitimate Resource Name or Location

Sibot has downloaded a DLL to the C:\windows\system32\drivers\ folder and renamed it with a .sys extension.

T1047
Windows Management Instrumentation

Sibot has used WMI to discover network connections and configurations. Sibot has also used the Win32_Process class to execute a malicious DLL.

T1049
System Network Connections Discovery

Sibot has retrieved a GUID associated with a present LAN connection on a compromised machine.

T1053.005
Scheduled Task

Sibot has been executed via a scheduled task.

T1059.005
Visual Basic

Sibot executes commands using VBScript.

T1070
Indicator Removal

Sibot will delete an associated registry key if a certain server response is received.

T1070.004
File Deletion

Sibot will delete itself if a certain server response is received.

T1071.001
Web Protocols

Sibot communicated with its C2 server via HTTP GET requests.

T1102
Web Service

Sibot has used a legitimate compromised website to download DLLs to the victim's machine.

T1105
Ingress Tool Transfer

Sibot can download and execute a payload onto a compromised system.

T1112
Modify Registry

Sibot has modified the Registry to install a second-stage script in the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\sibot.

View all 18 procedure examples

Groups that use it1

Campaigns1

References1

  1. MSTIC NOBELIUM Mar 2021 Open source
    Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.