Sowbug
Overview
Sowbug is a threat group that has conducted targeted attacks against organizations in South America and Southeast Asia, particularly government entities, since at least 2015.
Naming & attribution
Sowbug is tracked under 1 names across the industry. It uses 9 documented ATT&CK techniques — more than 26% of the 174 groups tracked here. Activity attributed since at least 2015.
| Name | First reported by |
|---|---|
| Sowbug | Symantec Security Response |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
Malware families with current indicators
One family attributed to Sowbug, carrying 15 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- StarLoader 15 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Targets
Government
Regions
Argentina · Brazil · Brunei · Ecuador · Malaysia · Peru
TTPs — 9 techniques across 5 tactics
Execution
-
T1059.003Windows Command Shell
Stealth
Credential Access
-
T1003OS Credential Dumping
Discovery
-
T1082System Information Discovery -
T1083File and Directory Discovery -
T1135Network Share Discovery
Collection
-
T1039Data from Network Shared Drive -
T1056.001Keylogging -
T1560.001Archive via Utility
Tools & malware (2)
Starloader · Felismus
Reporting (1)
- Sowbug: Cyber espionage group targets South American and Southeast Asian governments — Symantec Security Response