Netskope Threat Labs

Sdbot

ATP Sandbox Adv. HeuristicsAV

SdBot (a.k.a. SDBot) is an IRC based backdoor and worm that provides remote access capabilities and spreads through network shares. Infected systems connect to chat channels where operators issue commands, and the malware's simple, scriptable design spawned many variants across the early 2000s. Modern detections usually indicate legacy infections on unmanaged systems, but the IRC control channel pattern still appears in contemporary IoT malware.

First seen
January 2022
Last seen
October 2026
SDBotSDbotSdBot
Alert Name
Backdoor.SdBot.BZJ
Backdoor.SDbot.DFNQ
Backdoor.SdBot.DFSG
Backdoor.SDBot.DFSX
Backdoor.SDBot.DFUF
Backdoor.SDBot.DGCH
DeepScan:Generic.Sdbot.05DEE2DA
DeepScan:Generic.Sdbot.0648B0A1
DeepScan:Generic.Sdbot.0B5AEF09
DeepScan:Generic.Sdbot.0BBB2E62