Sykipot is a Windows espionage malware family associated with Chinese state-linked intrusion activity. It has been used in targeted operations against organizations in the U.S. defense industrial base as well as telecommunications, computer hardware, aerospace, and government contractor sectors. The malware exhibits classic remote-access and post-compromise tradecraft, including host and network reconnaissance, credential collection, persistence, encrypted command-and-control communications, and process injection.
Observed functionality includes enumerating running processes, collecting local network configuration details, identifying privileged accounts and administrator group membership, discovering remote systems on the network, and listing running services. Sykipot also contains keylogging capability for credential theft and has been observed injecting itself into legitimate user processes, including web browsers and email client processes, to evade detection and blend malicious activity with normal application behavior. For persistence, it has been reported to establish autorun execution through Windows Registry Run entries. Its command-and-control traffic has been observed protected with SSL encryption.
Sykipot is best characterized as a targeted backdoor or remote access trojan used in espionage-focused intrusions rather than indiscriminate cybercrime. Reporting has also noted infrastructure overlap between Sykipot activity and a PlugX-related cluster, suggesting operational relationships or shared resources within broader Chinese intrusion ecosystems, though such overlap alone does not establish malware equivalence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
“P.L.A. Unit 61398 attacked Digital Bond, a SCADA security company with a spear phishing attack.” / “Chinese hackers engaged in a phishing campaign aimed at compromising hundreds of Gmail passwords…” / “Alleged Chinese hackers posed as C-Suite executives in a spear phishing campaign to access the network of Alcoa.”
"The National Defense University discovered Chinese malware in its computer systems." and repeated references to intrusions involving malware (e.g., Luckycat; Sykipot; malware spread to foreign government websites).
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
"The National Defense University discovered Chinese malware in its computer systems." and repeated references to intrusions involving malware (e.g., Luckycat; Sykipot; malware spread to foreign government websites).
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
"actors used the following command ... to obtain information about services: net start"; "APT1 used the commands net start and tasklist to get a listing of the services on the system"; "OilRig has used sc query on a victim to gather information about services"; "Indrik Spider has used the win32_service WMI class to retrieve a list of services"
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Brute Ratel C4 can use LDAP queries, net group "Domain Admins" /domain and net user /domain for discovery. OilRig has run net group "domain admins" /domain and net group "Exchange Trusted Subsystem" /domain to get account listings on a victim. Wizard Spider has identified domain admins through the use of net group "Domain admins" /DOMAIN.
Multiple actors and tools are described enumerating domain users/admins via Windows net commands (e.g., net user /domain, net group "Domain Admins" /domain), LDAP/AD queries (e.g., Get-ADUser, Get-ADGroupMember), and AD enumeration utilities (e.g., AdFind, BloodHound, AD Explorer).
Repeated throughout: “stole trade secret information…”, “stole sensitive military information…”, “stole personal information…”
“Chinese hackers used malware, known as ‘Sykipot’…” / “discovered Chinese malware in its computer systems.” / “used their access to spread malware to foreign government websites.”
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware family used in China-linked cyber-espionage to compromise and maintain access to targeted organizations, particularly in defense and high-technology sectors.
A China-linked remote access/backdoor malware family used for cyber-espionage against defense and other strategic industries, enabling persistent access and data theft.
A China-linked malware family used in cyber-espionage to compromise and maintain access to targeted organizations, particularly in defense and high-technology sectors.
A China-linked malware family used for cyber-espionage to compromise and maintain access to targeted organizations, particularly in defense and high-technology sectors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.