Description
Sibot is dual purpose malware written in VBScript that achieves persistence on compromised systems and downloads and executes additional payloads. Microsoft discovered three variants in early 2021 during its investigation of APT29 and the SolarWinds Compromise.
Stats
- First seen
- March 2022
- Last seen
- October 2026
Also known as
SiBot
MITRE ATT&CK techniques
18 techniques across 5 tactics.
TA0002 Execution
TA0005 Stealth
TA0007 Discovery
TA0011 Command and Control
TA0112 Defense Impairment
- T1112Modify Registry
Associated groups
Associated campaigns
Alert name variants
| Alert Name |
|---|
| Script-WScript.Trojan.Sibot |
| Script-WScript.Trojan.SiBot |