Sowbug is an espionage-oriented intrusion set associated with targeted post-compromise collection activity. The group has been observed using Windows command shell activity during intrusions, conducting host and network reconnaissance, harvesting credentials, capturing keystrokes, and collecting documents for exfiltration. Reported behavior includes enumerating operating system version and hardware configuration, identifying installed software, listing accessible remote shared drives, and searching file servers for documents of interest, including Word documents filtered by extension and date range. Sowbug has also bundled collected documents into archives prior to exfiltration. The actor employs defense-evasion through masquerading, naming tools to resemble legitimate Windows or Adobe software. Its tradecraft reflects a conventional hands-on post-exploitation workflow focused on discovery, credential access, collection, and data theft rather than disruptive or ransomware operations. Known aliases directly supported here are limited to Sowbug.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor associated with the Network Share Discovery technique (T1135).
Listed as a threat actor associated with Windows Command Shell execution behavior relevant to this detection.
Referenced as a threat actor associated with credential access behavior, specifically techniques involving unsecured credentials and OS credential dumping in the context of LAPS password gathering via PowerShell.
Listed as a threat actor associated with WinPEAS-related post-exploitation/reconnaissance activity in the detection metadata.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.