Drovorub is a modular Linux malware framework attributed by U.S. government agencies to Russia’s GRU 85th Main Special Service Center, specifically Unit 26165, which is widely tracked as APT28 or Fancy Bear. It has been associated with cyber espionage operations and is designed to establish covert, durable access on Linux systems.
The framework comprises multiple components including a client implant, an agent, a server-side command-and-control component, and a kernel-module rootkit. Its components communicate using JSON over WebSockets, and the malware has been documented using TCP between internal modules. The client component supports remote shell access, file transfer, and port forwarding. The agent component is used for file upload, file download, and relaying network traffic, including forwarding traffic through compromised hosts to reach other systems on the same network.
A defining feature of Drovorub is its Linux kernel rootkit, which provides stealth by hiding itself and associated user-space artifacts. Reported hiding capabilities include concealing files, directories, processes, child processes, network ports, and network sessions, making host-based detection and live-response collection significantly more difficult. The malware has also been observed de-obfuscating XOR-encrypted payloads carried in WebSocket messages.
Operationally, Drovorub supports file theft and exfiltration over its command-and-control infrastructure, transfer of files from victim machines, and deletion of specific files on compromised hosts. These capabilities make it suitable for post-compromise espionage, persistence, covert remote administration, and internal pivoting within targeted environments.
Drovorub is notable as a high-profile Linux threat and has been publicly characterized as a previously undisclosed malware toolset used in real-world intrusions. It has been highlighted as an example of Russian state-sponsored Linux malware used to plant backdoors in victim networks and maintain stealthy access for follow-on operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Today, Insane Forensics makes public a free, open source tool to assist with scaled network detection and response for GRUs Drovorub malware using Elasticsearch and Kibana.
the U.S. Government assesses that GTsSS cyber actors have deployed Drovorub malware against victim devices as part of their cyber espionage operations.
Furthermore, the Drovorub malware used in the conduct of cyberespionage activities is attributed to have its origin within the GRU.
NSA/FBI. (2020, August). Russian GRU 85th GTsSS Deploys Previously Undisclosed Drovorub Malware.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Drovorub is a multi-component system that comes with an implant, a kernel module rootkit, a file transfer tool, a port-forwarding module, and a command-and-control (C2) server.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The provided dashboard allows for primary hunting and response techniques covering Drovorub's command and control (c2). Drovorub C2 uses the WebSockets protocol outlined in RFC 6455. | Drovorub C2 uses the WebSockets protocol outlined in RFC 6455. All WebSocket communications will appear in the source, destination, and network protocol panels of the provided dashboard.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
The tunnel local connection and tunnel remote connection panes above show tunnel information used by Drovorub's tunnel module.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparator Linux rootkit that uses a single pre-compiled kernel module, limiting kernel compatibility.
Malware attributed to the GRU and used for cyberespionage activities.
Malware/rootkit capable of exfiltrating files over command-and-control infrastructure.
Malware toolkit/rootkit that can transfer files from victim machines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.