Derusbi (ELF)
- First seen
- 2011-01-01 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 12:36:12
Targeted industries: defense-and-aerospace government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:cn country_code:jp
Context
Derusbi is a backdoor often used by Chinese advanced persistent threat (APT) groups. It primarily targets government, defense, and technology sectors to facilitate cyber espionage.
Reports & references
- MITRE ATT&CK — G0001 (report)
- MITRE ATT&CK — G0096 (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Derusbi (report)
- twitter.com — 1407676522534735873 (report)