S0021WindowsLinux

S0021Derusbi

Platforms
2
ATT&CK
14.1
References
5

Description

[Derusbi](https://attack.mitre.org/software/S0021) is malware used by multiple Chinese APT groups.(Citation: Novetta-Axiom)(Citation: ThreatConnect Anthem) Both Windows and Linux variants have been observed.(Citation: Fidelis Turbo) Documented platforms: Windows, Linux. Catalogued in ATT&CK 14.1. 5 references curated.

Platforms· 2

WindowsLinux

References

  1. https://attack.mitre.org/software/S0021
  2. https://paper.seebug.org/papers/APT/APT_CyberCriminal_Campagin/2016/2016.02.29.Turbo_Campaign_Derusbi/TA_Fidelis_Turbo_1602_0.pdf
  3. https://www.fireeye.com/blog/threat-research/2018/03/suspected-chinese-espionage-group-targeting-maritime-and-engineering-industries.html
  4. https://web.archive.org/web/20230115144216/http://www.novetta.com/wp-content/uploads/2014/11/Executive_Summary-Final_1.pdf
  5. https://www.threatconnect.com/the-anthem-hack-all-roads-lead-to-china/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
Zebrocy
Software
Uroburos
Software
Daserf
Software
Drovorub
Software
Ixeshe
Software
Fysbis
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.