Sowbug

🔴 High
Also known as: G0054, Sowbug

Sowbug is a threat group that has conducted targeted attacks against organizations in South America and Southeast Asia, particularly government entities, since at least 2015. Symantec Sowbug Nov 2017

🌍 Country Unknown
Risk Level High
🎯 Incident Type Espionage
🧭 ATT&CK G0054
Government

Introduction

Sowbug is a threat group that has conducted targeted attacks against organizations in South America and Southeast Asia, particularly government entities, since at least 2015. Symantec Sowbug Nov 2017

Activities and Tactics

Targeted Sectors: Government

Country of Origin: 🏳️ Unknown

Risk Level: High

Incident Type: Espionage

Suspected Victims: Argentina, Ecuador, Brazil, Brunei, Peru, Malaysia

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • CyberGate
  • Cyber Eye RAT
  • Felismus:

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: Unknown Additional attribution information pending cataloguing.

References

[1] mitre-attack [3] Symantec Sowbug Nov 2017 Symantec Security Response. (2017, November 7). Sowbug: Cyber espionage group targets South American and Southeast Asian governments. Retrieved November 16, 2017.