Sowbug
Overview
Sowbug is a threat group that has conducted targeted attacks against organizations in South America and Southeast Asia, particularly government entities, since at least 2015.
Naming & attribution
It uses 9 documented ATT&CK techniques — more than 26% of the 174 groups tracked here. Activity attributed since at least 2015.
| Name | First reported by |
|---|---|
| Sowbug | Symantec Security Response |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
Malware families with tracked indicators
One family attributed to Sowbug, with 15 deduplicated indicators observed across abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL over the corpus's window (up to three years, as of 2026-09-26). MITRE documents what a group does; these are the indicators its malware families have surfaced in that window.
- StarLoader 15 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Targets
Regions
Argentina · Brazil · Brunei · Ecuador · Malaysia · Peru
TTPs — 9 techniques across 5 tactics
Execution
-
T1059.003Windows Command Shell
Stealth
Credential Access
-
T1003OS Credential Dumping
Discovery
-
T1082System Information Discovery -
T1083File and Directory Discovery -
T1135Network Share Discovery
Collection
-
T1039Data from Network Shared Drive -
T1056.001Keylogging -
T1560.001Archive via Utility
Tools & malware (2)
Starloader · Felismus
Reporting (1)
- Sowbug: Cyber espionage group targets South American and Southeast Asian governments — Symantec Security Response