DBoxAgent (Malware Family) By Fraunhofer FKIE Archived: 2026-04-06 00:11:22 UTC win.dboxagent (Back to overview) DBoxAgent Actor(s): APT41 This malware uses DropBox as C&C channel. References 2020-10-12 ⋅ Malwarebytes Labs ⋅ Hossein Jazi, Jérôme Segura, Malwarebytes Threat Intelligence Team, Roberto Santos Winnti APT group docks in Sri Lanka for new campaign DBoxAgent SerialVlogger Winnti There is no Yara-Signature yet. Source: https://malpedia.caad.fkie.fraunhofer.de/details/win.dboxagent https://malpedia.caad.fkie.fraunhofer.de/details/win.dboxagent Page 1 of 1