Netskope Threat Labs

Sibot

ATP Sandbox Adv. Heuristics

Sibot is dual purpose malware written in VBScript that achieves persistence on compromised systems and downloads and executes additional payloads. Microsoft discovered three variants in early 2021 during its investigation of APT29 and the SolarWinds Compromise.

First seen
March 2022
Last seen
October 2026
SiBot

18 techniques across 5 tactics.

TA0002 Execution

TA0005 Stealth

TA0007 Discovery

  • T1012Query Registry
  • T1016System Network Configuration Discovery
  • T1049System Network Connections Discovery

TA0011 Command and Control

TA0112 Defense Impairment

Alert Name
Script-WScript.Trojan.Sibot
Script-WScript.Trojan.SiBot