Derusbi is a backdoor family with Windows and Linux variants used by multiple China-linked espionage actors, including Axiom, APT19, Deep Panda, and Winnti-associated operators. It has been observed in telecommunications environments and supports remote access, surveillance, and post-compromise operations.
Its capabilities include keystroke logging, screen capture, victim-username collection, and collection of process identifiers. Windows variants collect detailed host, network, hardware, and locale information and transmit it to command-and-control infrastructure. Server-side variants support arbitrary command execution, interactive remote shells, service and process management, registry manipulation, file browsing and transfer, port forwarding, proxy operation, and downloading and executing additional DLL modules. Communication mechanisms include raw sockets, outbound connections, listening-mode operation, and fallback HTTP beaconing. Some variants obfuscate command-and-control traffic with variable four-byte XOR keys.
Windows persistence mechanisms include service creation or hijacking and registry-based startup, sometimes using a legitimate DLL registration utility to proxy execution. Derusbi has also been deployed through the HDRoot bootkit. Associated kernel drivers conceal files and network activity and redirect specially crafted incoming packets to the backdoor. Windows variants have abused a vulnerable Novell driver to modify code-integrity settings and have used stolen signing certificates. Linux variants check for root privileges, inject into the SSH process, and have loaded kernel modules before deleting and overwriting their on-disk artifacts. Additional evasion behaviors include timestamp manipulation, artifact deletion, and execution-context checks intended to hinder analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
FireEye reported that APT19 was active in 2017 when they used 3 different methods to compromise targets: CVE-2017-0199 vulnerability, macro-enabled Microsoft Excel (XLSM) documents and an application whitelisting bypass to the XLSM documents. | In this blog post we’re presenting a full analysis of a DLL backdoor also reported publicly as Derusbi. This particular piece of malware is associated with the actor known as APT19
PHOTO, BADFLICK, and CHINA CHOPPER are among the most frequently observed backdoors used by APT40.
PHOTO, BADFLICK, and CHINA CHOPPER are among the most frequently observed backdoors used by APT40.
PHOTO, BADFLICK, and CHINA CHOPPER are among the most frequently observed backdoors used by APT40.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Derusbi variants have been seen that use Registry persistence to proxy execution through regsvr32.exe.
Axiom Derusbi 9002 RAT BLACKCOFFEE Derusbi Ghost RAT HiKit PlugX ZXShell APT17
This is the malware family known as server-side Derusbi, which we observed during several Winnti-related incidents.
In this blog post we’re presenting a full analysis of a DLL backdoor also reported publicly as Derusbi. This particular piece of malware is associated with the actor known as APT19
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Several entries describe identifying whether the current user has admin privileges, determining privilege level, identifying groups the user belongs to, or verifying execution as SYSTEM.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
62 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
Derusbi is listed as malware relevant to the detection's analytic stories, implying possible use of DLL side-loading or related tradecraft. No further description is provided in the content.
Associated Analytic Story ... Derusbi
Derusbi is referenced as a backdoor/RAT in suspicious execution and driver-loading detections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.