AgfSpy

Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 13:09:35

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

The agfSpy backdoor retrieves configuration and commands from its C&C server. These commands allow the backdoor to execute shell commands and send the execution results back to the server. It also enumerates directories and can list, upload, download, and execute files, among other functions. The capabilities of agfSpy are very similar to dneSpy, except each backdoor uses a different C&C server and various formats in message exchanges.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Agfspy_Auto (yara-rule)

Reports & references

  • Trend Micro — Operation Earth Kitsune A Dance Of Two New Backdoors (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Agfspy (report)

External references