DneSpy
- First seen
- 2017-03-01 00:00:00
- Malware type
- backdoor, spyware, screen-capture
- Family
- Malware family
- Profile updated
- 2026-07-07 13:09:32
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
DneSpy collects information, takes screenshots, and downloads and executes the latest version of other malicious components in the infected system. The malware is designed to receive a “policy” file in JSON format with all the commands to execute. The policy file sent by the C&C server can be changed and updated over time, making dneSpy flexible and well-designed. The output of each executed command is zipped, encrypted, and exfiltrated to the C&C server. These characteristics make dneSpy a fully functional espionage backdoor.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Dnespy_Auto (yara-rule)
Reports & references
- Trend Micro — Operation Earth Kitsune A Dance Of Two New Backdoors (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Dnespy (report)