Netskope Threat Labs

TrueBot

ATP Sandbox Adv. HeuristicsNetskope IPS

TrueBot is a downloader and botnet client that cyberattackers use to gain initial access to corporate networks. The Silence threat group has used it against financial institutions, and researchers have observed it delivering heavier payloads such as FlawedAmmyy and ransomware after harvesting data from infected machines.

First seen
February 2022
Last seen
October 2026
Truebot
Alert Name
Win32.Backdoor.Truebot
Win32.Backdoor.TrueBot
Win32.Trojan.Truebot
Win32.Trojan.TrueBot
Win64.Backdoor.Truebot
Win64.Backdoor.TrueBot
Win64.Trojan.TrueBot