Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Malware

Sykipot

Sykipot is malware referenced in reporting on Chinese cyber operations. In September 2013, Chinese hackers used Sykipot to target entities in the U.S. defense industrial base as well as organizations in telecommunications, computer hardware, government contracting, and aerospace. Reported behavior includes account and privilege discovery using commands such as net group "domain admins" /domain and net localgroup "administrators" to enumerate privileged group membership, remote system discovery using net view /domain to list hostnames of available systems on a network, and service discovery using net start to display running services. Sykipot also uses SSL to encrypt command-and-control communications.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

27 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1587.001MalwareEvidence1

“The National Defense University discovered Chinese malware in its computer systems.” / “used malware, known as ‘Sykipot’, to target entities in the U.S. defense industrial base…” / “campaign… used their access to spread malware to foreign government websites.”

Initial Access

2 techniques
T1566PhishingEvidence1

“P.L.A. Unit 61398 attacked Digital Bond, a SCADA security company with a spear phishing attack.” / “Chinese hackers engaged in a phishing campaign aimed at compromising hundreds of Gmail passwords…” / “Alleged Chinese hackers posed as C-Suite executives in a spear phishing campaign to access the network of Alcoa.”

T1566.001Spearphishing AttachmentEvidence1

“P.L.A. Unit 61398 attacked Digital Bond, a SCADA security company with a spear phishing attack.” / “Alleged Chinese hackers posed as C-Suite executives in a spear phishing campaign to access the network of Alcoa.”

Execution

2 techniques
T1204User ExecutionEvidence1

"The National Defense University discovered Chinese malware in its computer systems." / "Chinese hackers used malware, known as ‘Sykipot’"

T1204.002Malicious FileEvidence1

"January 2007: The National Defense University discovered Chinese malware in its computer systems."; "September 2013... used malware, known as ‘Sykipot’"

Persistence

2 techniques
T1543Create or Modify System ProcessEvidence1

"The National Defense University discovered Chinese malware in its computer systems." and repeated references to intrusions involving malware (e.g., Luckycat; Sykipot; malware spread to foreign government websites).

T1547.001Registry Run Keys / Startup FolderEvidence4

The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, or .lnk files in the Startup folder.

Privilege Escalation

3 techniques
T1055.001Dynamic-link Library InjectionEvidence1
T1543Create or Modify System ProcessEvidence1

"The National Defense University discovered Chinese malware in its computer systems." and repeated references to intrusions involving malware (e.g., Luckycat; Sykipot; malware spread to foreign government websites).

T1547.001Registry Run Keys / Startup FolderEvidence4

The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, or .lnk files in the Startup folder.

Stealth

1 technique
T1055.001Dynamic-link Library InjectionEvidence1

Credential Access

3 techniques
T1056.001KeyloggingEvidence1
T1111Multi-Factor Authentication InterceptionEvidence1
T1649Steal or Forge Authentication CertificatesEvidence1

Throughout the timeline: repeated “stole trade secret information” across aerospace, automotive, chemicals, semiconductors, pharma, agriculture, etc.

Discovery

8 techniques
T1007System Service DiscoveryEvidence2

"actors used the following command ... to obtain information about services: net start"; "APT1 used the commands net start and tasklist to get a listing of the services on the system"; "OilRig has used sc query on a victim to gather information about services"; "Indrik Spider has used the win32_service WMI class to retrieve a list of services"

T1016System Network Configuration DiscoveryEvidence4

The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.

T1018Remote System DiscoveryEvidence2

During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.

T1049System Network Connections DiscoveryEvidence1
T1057Process DiscoveryEvidence3

The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.

T1069.002Domain GroupsEvidence1

Brute Ratel C4 can use LDAP queries, net group "Domain Admins" /domain and net user /domain for discovery. OilRig has run net group "domain admins" /domain and net group "Exchange Trusted Subsystem" /domain to get account listings on a victim. Wizard Spider has identified domain admins through the use of net group "Domain admins" /DOMAIN.

T1087Account DiscoveryEvidence1

Multiple actors and tools are described enumerating domain users/admins via Windows net commands (e.g., net user /domain, net group "Domain Admins" /domain), LDAP/AD queries (e.g., Get-ADUser, Get-ADGroupMember), and AD enumeration utilities (e.g., AdFind, BloodHound, AD Explorer).

T1087.002Domain AccountEvidence2

AdFind can enumerate domain users. APT41 used built-in net commands to enumerate domain administrator users. BloodHound can collect information about domain users, including identification of domain admin accounts.

Collection

3 techniques
T1005Data from Local SystemEvidence1

Repeated throughout: “stole trade secret information…”, “stole sensitive military information…”, “stole personal information…”

T1056.001KeyloggingEvidence1
T1213Data from Information RepositoriesEvidence1

“Chinese hackers… stole trade secret information…” (multiple incidents across aerospace, energy, pharma, and government)

Command and Control

3 techniques
T1105Ingress Tool TransferEvidence1

“Chinese hackers used malware, known as ‘Sykipot’…” / “discovered Chinese malware in its computer systems.” / “used their access to spread malware to foreign government websites.”

T1573Encrypted ChannelEvidence1

The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.

T1573.002Asymmetric CryptographyEvidence2

Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").

Exfiltration

2 techniques
T1020Automated ExfiltrationEvidence1

“Chinese hackers exfiltrated national security information…”, “exfiltrated information about the Space Shuttle Discovery program…”, “stole trade secret information…”, “614 gigabytes of material… were taken…”

T1041Exfiltration Over C2 ChannelEvidence1

Multiple entries describe “exfiltrated” or “stole” data (e.g., “exfiltrated information…”, “downloading 10 to 20 terabytes of data”, “stole 614 gigabytes of material…”).

Impact

1 technique
T1657Financial TheftEvidence1

Numerous entries: "stole trade secret information" across aerospace, automotive, chemicals, semiconductors, pharma, agriculture, etc.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping27

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.