SDBbot is a Windows remote access trojan and backdoor closely associated with the TA505 cybercrime ecosystem and observed since at least September 2019. It has been used as a second-stage payload delivered by the Get2 downloader and has appeared in intrusion chains that later culminated in enterprise ransomware deployment, particularly Clop. SDBbot is notable for being comparatively uncommon outside TA505-linked activity and has been assessed as part of the group’s shift from broad malware distribution toward hands-on-keyboard compromise, privilege escalation, lateral movement, and big-game hunting operations.
On infected hosts, SDBbot supports remote control and post-compromise operations including command execution, file-system access, file deletion, file download, screen streaming, TCP forwarding, host reboot, user identification, and collection of local environment details such as domain name and proxy configuration. It can decrypt and decompress embedded payload components to enable execution, and it has been observed injecting a downloaded DLL into a newly created rundll32.exe process. In some intrusions it ran with elevated privileges inside legitimate Windows processes, reflecting its use as an operational backdoor rather than a simple commodity implant.
SDBbot employs stealth-oriented persistence mechanisms. It has been observed storing payload and configuration data in the Windows Registry and using Registry Run-key persistence when operating in user context. Reporting also links some variants to application shimming for persistence when running with higher privileges. Samples may use unique bootstrap components and registry-resident second stages, complicating static detection and making public sample availability relatively limited.
Operationally, SDBbot has been tied to phishing-led intrusion chains in which malicious documents or links deliver Get2, which performs reconnaissance and selectively retrieves SDBbot for follow-on access. Once deployed, SDBbot has served as an origin point for broader compromise, enabling operators to return to victim environments, expand access, and prepare ransomware deployment. Multiple analyses have linked SDBbot-enabled intrusions to later Clop ransomware activity, reinforcing its role as a precursor backdoor in financially motivated enterprise attacks affecting sectors including healthcare and other large organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Four hours after the implant was installed, the attackers connected back to the target. One hour later, they used MS17-07 directly against one domain controller to gain AD domain admin rights.
The opening of the malicious attachment to a phishing email led to the installation of the tool Get2 and the Remote Access Trojan, SDBBOT, which was used to establish persistence on the endpoint.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PROOFPOINT. TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader.
After the initial breach, the attackers installed a backdoor commonly named SDBbot... This backdoor allows the assailants to control the host.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
TA505 semble avoir procédé à la distribution de ses charges malveillantes uniquement par campagnes de courriels d’hameçonnage... L’unique vecteur d’infection pour l’instant connu du mode opératoire TA505 demeure le courriel d’hameçonnage incluant une pièce jointe ou un lien malveillant.
These attachments could be zip or 7zip archives containing VBS script or Javascript to be run by their victims, HTML pages containing malicious Javascript, or Offices documents bugged with malicious macros.
L’unique vecteur d’infection pour l’instant connu du mode opératoire TA505 demeure le courriel d’hameçonnage incluant une pièce jointe ou un lien malveillant... ce dernier envoyait directement des liens vers ses pages d’hameçonnage dans ses courriels malveillants.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
La victime est alors incitée à télécharger, ouvrir et activer les macros VBA d’un document Office, généralement Excel, contenant une charge malveillante.
This intrusion set relies exclusively over that period on social engineering to run its payload contained in malicious attachments linked to emails sent... The victim is then encouraged to download, open and enable VBA macros of an Office document.
This code redirects the victim towards an URL of a legitimate but compromised website... The victim is then encouraged to download, open and enable VBA macros of an Office document.
Ce mode opératoire s’appuie exclusivement durant cette période sur de l’ingénierie sociale pour faire exécuter ses charges contenues dans des pièces jointes malveillantes... La victime est alors incitée à télécharger, ouvrir et activer les macros VBA d’un document Office. | Le but de ces documents était souvent d’exécuter via des macros des commandes msiexec sur la machine de la victime pour télécharger et exécuter un code malveillant.
SDBBot 원격제어 악성코드는 이러한 정상적인 목적으로 제공된 애플리케이션 패치 메커니즘을 악용하여 동작한다... 이후 악성 SDB 파일을 생성하고 sdbinst.exe를 이용해 등록한다.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
SDBBot 원격제어 악성코드는 이러한 정상적인 목적으로 제공된 애플리케이션 패치 메커니즘을 악용하여 동작한다... 이후 악성 SDB 파일을 생성하고 sdbinst.exe를 이용해 등록한다.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
In malware, we often see threat actors that tend to obfuscate or encrypt their code in order to slow down the analysis of security researchers... many authors tend to use open-source packers but also craft their own custom packers.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Examples in the content include 'DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules,' 'Molerats decompresses ZIP files once on the victim machine,' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
116 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
57 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family observed as a payload in StealC-related delivery chains.
SDBbot was observed as a payload in StealC-related operations.
Backdoor used to establish persistence after initial phishing compromise in an intrusion associated with Cl0p ransomware activity.
Mentioned for code similarity in a PE-module loader; not part of the incident.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.