Derusbi is a long-running backdoor and remote access trojan family associated with multiple Chinese espionage clusters, including reporting linking variants to APT19, APT17/DeputyDog-era activity, and Winnti-related intrusions. It has been in use since at least 2008 and exists in both Windows and Linux forms, with some reporting also referring to the Linux variant as Photo. Derusbi has been deployed in targeted intrusions against government and enterprise environments and has appeared in incidents affecting organizations in Asia and other regions.
Derusbi is a fully featured espionage backdoor oriented toward persistent remote control and host surveillance. Reported capabilities include collection of host profiling data such as usernames and process information, screen capture, keylogging, registry enumeration, arbitrary command execution, file browsing and transfer, service and process management, proxy functionality, and interactive shell access. Some variants support fallback communications, including backup HTTP beaconing, and obfuscate command-and-control traffic with XOR-based encoding. Windows variants have been observed establishing persistence through services or Registry-based mechanisms, including proxy execution through regsvr32.exe. Linux variants have been observed requiring root privileges before execution.
Operational tradecraft varies by lineage. Windows DLL variants have used anti-analysis checks tied to expected execution through rundll32.exe and can retrieve and execute secondary DLL payloads in memory. Winnti-linked server-side Derusbi variants have been observed alongside kernel-mode components that hide artifacts and network activity, support listening-mode operation, and enable covert remote shell access. Linux variants have been observed injecting into SSH-related processes and deleting loaded kernel modules from disk, including overwriting artifacts, indicating strong defense-evasion and anti-forensics intent.
Derusbi is best characterized as an espionage backdoor/RAT family used in targeted operations rather than commodity malware. Its cross-platform implementations, surveillance functions, persistence options, process injection behavior, and resilient command-and-control design make it a notable long-lived implant family in the Chinese APT ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
FireEye reported that APT19 was active in 2017 when they used 3 different methods to compromise targets: CVE-2017-0199 vulnerability, macro-enabled Microsoft Excel (XLSM) documents and an application whitelisting bypass to the XLSM documents. | In this blog post we’re presenting a full analysis of a DLL backdoor also reported publicly as Derusbi. This particular piece of malware is associated with the actor known as APT19
PHOTO, BADFLICK, and CHINA CHOPPER are among the most frequently observed backdoors used by APT40.
PHOTO, BADFLICK, and CHINA CHOPPER are among the most frequently observed backdoors used by APT40.
PHOTO, BADFLICK, and CHINA CHOPPER are among the most frequently observed backdoors used by APT40.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Derusbi variants have been seen that use Registry persistence to proxy execution through regsvr32.exe.
Axiom Derusbi 9002 RAT BLACKCOFFEE Derusbi Ghost RAT HiKit PlugX ZXShell APT17
This is the malware family known as server-side Derusbi, which we observed during several Winnti-related incidents.
In this blog post we’re presenting a full analysis of a DLL backdoor also reported publicly as Derusbi. This particular piece of malware is associated with the actor known as APT19
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
Tools Nanhaishu, Orz, SeDll, Cobalt Strike, GreenCrash, AIRBREAK, BlackCoffee, China Chopper, FUSIONBLAZE, HOMEFRY, MURKYTOP, Metasploit / Meterpreter, ScanBox, Derusbi Trojan, Derusbi, Metasploit
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution of arbitrary files or shell commands on infected system ... The library is run by executing the following command line: rundll32.exe %Systemroot%\Help\perfc009.dat R32 <random_number> ... cmd.exe /c net stop sharedaccess
FireEye reported that APT19 was active in 2017 when they used 3 different methods to compromise targets: CVE-2017-0199 vulnerability, macro-enabled Microsoft Excel (XLSM) documents and an application whitelisting bypass to the XLSM documents.
FireEye reported that APT19 was active in 2017 when they used 3 different methods to compromise targets: CVE-2017-0199 vulnerability, macro-enabled Microsoft Excel (XLSM) documents and an application whitelisting bypass to the XLSM documents.
Services management: list of services, creating, starting, stopping, deleting services
altered files on legitimate update servers or DNAT configuration changes in iptables resulted in software update requests being redirected to an illegitimate server
It puts a string with its own path to the “ServiceDll” value in the registry that associates with the “iphlpsvc” or “wuauserv” system service depending on Windows version, and saves the original value of “ServiceDll” in encrypted form to the “Security” parameter of the same registry key.
The malware stores its configuration data in encrypted form in the “Security” value of the HKLM\SOFTWARE\Microsoft\Rpc registry key.
The malware registers itself as a service if it has run with administrator privileges... There is another service called WinHelpSrv that is added to this list... The file creates a new service named WinHelpSrv (Windows Helper Service)... The malicious DLL is registered as a service by adding the “ServiceDll” value that points to its location.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
The malware registers itself as a service if it has run with administrator privileges... There is another service called WinHelpSrv that is added to this list... The file creates a new service named WinHelpSrv (Windows Helper Service)... The malicious DLL is registered as a service by adding the “ServiceDll” value that points to its location.
The rootkit conceals malicious network activity from popular network monitoring tools by hooking the IRP_MJ_DIRECTORY_CONTROL service routine of “DeviceTcp” or “Driver\nsiproxy” system objects. It also hides the file “windows\system32\wiarpc.dll” from user-mode applications by hooking the IRP_MJ_DIRECTORY_CONTROL service routine of the file system driver “FileSystem\Ntfs”.
It copies itself to the folder “%System32%\wbem“, with a name consisting of “ntfs” + three random letters, and a “.mof” extension... Property Value FileDescription ProfSvc ... CompanyName Microsoft Corporation
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
AppleSeed can call regsvr32.exe for execution. APT19 used Regsvr32 to bypass application control techniques. APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory.
The library is run by executing the following command line: rundll32.exe %Systemroot%\Help\perfc009.dat R32 <random_number>
The malware uses an anti-analysis technique by comparing the image path of the executable with rundll32.exe. It is done to ensure that the file is not executed by a sandbox/analyst (it exits if that’s the case).
altered files on legitimate update servers or DNAT configuration changes in iptables resulted in software update requests being redirected to an illegitimate server
It puts a string with its own path to the “ServiceDll” value in the registry that associates with the “iphlpsvc” or “wuauserv” system service depending on Windows version, and saves the original value of “ServiceDll” in encrypted form to the “Security” parameter of the same registry key.
the malicious process allocates a new memory area in order to write the DLL code inside... the malware uses VirtualProtect in order to change the protection of the area... After the malicious code would be written in the new memory location, the process would pass the execution flow to the new DLL file
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
It sniffs all incoming network packets and searches them for a specially crafted signature. If found, it redirects these packets to the listening socket opened by the main malware module.
GetAdaptersInfo API is utilized to find adapter information for the local machine... The GetNetworkParams function is utilized to obtain network parameters for the local machine.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Several entries describe identifying whether the current user has admin privileges, determining privilege level, identifying groups the user belongs to, or verifying execution as SYSTEM.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
Machete has sent data over HTTP if FTP failed. Mis-Type first attempts to use a Base64-encoded network protocol over a raw TCP socket for C2, and if that method fails, falls back to a secondary HTTP-based protocol. NETEAGLE will send beacons via an HTTP POST request if the infected host is configured to a proxy.
Traffic redirection via port forwarding: infected host is used as proxy ... starting network proxy
According to the Unit42 article, the server would respond with a DLL file with 4 exports... the malicious process allocates a new memory area in order to write the DLL code inside... After the malicious code would be written in the new memory location, the process would pass the execution flow to the new DLL file.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
57 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
Derusbi is listed as malware relevant to the detection's analytic stories, implying possible use of DLL side-loading or related tradecraft. No further description is provided in the content.
Associated Analytic Story ... Derusbi
Derusbi is referenced as a backdoor/RAT in suspicious execution and driver-loading detections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.