{
  "family": "sdbot",
  "sample_count": 1931,
  "category": "rat",
  "description": "sdbot is classified as a remote access trojan (RAT), malware that gives an attacker remote control of an infected computer. It has one or more associated MITRE ATT&CK technique references (linked on this page) that document the behaviors observed for it. We have not yet published a hand-verified detailed profile for this family; the MITRE references below are the authoritative source for its documented techniques.",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "win32.sdbot",
    "sdbot.worm",
    "rbot",
    "spybot",
    "sdbot.a"
  ],
  "enrichment_level": "documented_reference_only",
  "faq": [
    {
      "@type": "Question",
      "name": "Where can I learn more about sdbot?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Refer to the linked MITRE ATT&CK technique pages, which document the behaviors associated with this family."
      }
    }
  ],
  "faq_count": 1,
  "mitre_attack": [
    "T1059.003",
    "T1071.003",
    "T1547.001",
    "T1105",
    "T1091",
    "T1498"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-06-09",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}