Derusbi (Windows)
Aliases: PHOTO
- First seen
- 2010-01-01 00:00:00
- Malware type
- backdoor, keylogger, screen-capture, spyware, trojan
- Family
- Malware family
- Last IoC activity
- 2026-06-11 09:15:04
- Profile updated
- 2026-07-07 12:36:10
Targeted industries: defense-and-aerospace government-and-public-sector technology-and-telecommunications
Context
A DLL backdoor also reported publicly as “Derusbi”, capable of obtaining directory, file, and drive listing; creating a reverse shell; performing screen captures; recording video and audio; listing, terminating, and creating processes; enumerating, starting, and deleting registry keys and values; logging keystrokes, returning usernames and passwords from protected storage; and renaming, deleting, copying, moving, reading, and writing to files.
Related threat objects
- Derusbi (malware)
Reports & references
- secureworks.com — Bronze Keystone (report)
- MITRE ATT&CK — G0001 (report)
- secureworks.com — Bronze Firestone (report)
- secureworks.com — Bronze Mohawk (report)
- MITRE ATT&CK — G0096 (report)
- rsa.com — Rsa Incident Response Emerging Threat Profile Shell Crew (report)
- threatconnect.com — The Anthem Hack All Roads Lead To China (report)
- web.archive.org — Globalthreatintelreport (report)
- Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
- Trend Micro — Biopass Rat New Malware Sniffs Victims Via Live Streaming (report)
- web.archive.org — Executive Summary Final 1 (report)
- nao-sec.org — An Overhead View Of The Royal Road (report)
- youtube.com — Watch (report)
- Palo Alto Unit 42 — Rancor Cyber Espionage Group Uses New Custom Malware To Attack Southeast Asia (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Derusbi (report)
- web.archive.org — Hta W02 Dissecting Derusbi (report)
- cybergeeks.tech — Analyzing Apt19 Malware Using A Step By Step Method (report)
- web.archive.org — Newcomers In The Derusbi Family (report)
- novetta.com — Derusbi (report)
- virusbulletin.com — Pun Etal Vb2015 (report)