A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #27972  by Blaze
 Tue Mar 01, 2016 12:43 pm
Derusbi for 64-bit Linux.

https://www.fidelissecurity.com/sites/d ... 283%29.pdf (PDF)
In the summer of 2015, Fidelis Cybersecurity had the opportunity to analyze a Derusbi malware sample used as part
of a campaign we’ve labeled Turbo, for the associated kernel module that was deployed. Derusbi has been widely
covered and associated with Chinese threat actors. This malware has been reported to have been used in high
profile breaches like the ones at Wellpoint/Anthem, VAE Inc, USIS and Mitsubishi Heavy Industries. Every one of these
campaigns involved a Windows version of Derusbi.
 #27991  by sww
 Thu Mar 03, 2016 12:03 pm
Looking for Linux KM sample [wil not share, if you want]. PM me. Thanks in advance!