Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-06 02:57:44 UTC Home > List all groups > List all tools > List all groups using tool DBoxAgent Tool: DBoxAgent Names DBoxAgent Category Malware Type Backdoor Description (Malwarebytes) The shellcode is a backdoor that gives the ability for attackers to control the victim's machine. We named this new backdoor DBoxAgent as it uses Dropbox as C&C. This way, attackers are able to circumvent network protection tools, as all communications are sent and received through Dropbox API. Information Malpedia Last change to this tool card: 22 June 2023 Download this tool card in JSON format All groups using tool DBoxAgent Changed Name Country Observed APT groups   APT 41 2012-Jul 2025 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=0f231c4c-6300-46ea-a1d0-6e3ee27f8288 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=0f231c4c-6300-46ea-a1d0-6e3ee27f8288 Page 1 of 1