AgfSpy
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 13:09:35
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
The agfSpy backdoor retrieves configuration and commands from its C&C server. These commands allow the backdoor to execute shell commands and send the execution results back to the server. It also enumerates directories and can list, upload, download, and execute files, among other functions. The capabilities of agfSpy are very similar to dneSpy, except each backdoor uses a different C&C server and various formats in message exchanges.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Agfspy_Auto (yara-rule)
Reports & references
- Trend Micro — Operation Earth Kitsune A Dance Of Two New Backdoors (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Agfspy (report)