DneSpy

First seen
2017-03-01 00:00:00
Malware type
backdoor, spyware, screen-capture
Family
Malware family
Profile updated
2026-07-07 13:09:32

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

DneSpy collects information, takes screenshots, and downloads and executes the latest version of other malicious components in the infected system. The malware is designed to receive a “policy” file in JSON format with all the commands to execute. The policy file sent by the C&C server can be changed and updated over time, making dneSpy flexible and well-designed. The output of each executed command is zipped, encrypted, and exfiltrated to the C&C server. These characteristics make dneSpy a fully functional espionage backdoor.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Dnespy_Auto (yara-rule)

Reports & references

  • Trend Micro — Operation Earth Kitsune A Dance Of Two New Backdoors (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Dnespy (report)

External references