
Anders Wilhelmsen

2026
Rootkits have been used since the 2000s by state-sponsored threat actors to enable covert network operations and hide from defenders. Derusbi, as one of the most prominent rootkits of the 2010s, was favoured among many of the well-known China-based groups of the time for its key functionality and capabilities remaining effective over years of operational usage.
ย Entering the 2020s, rootkits remain a key capability by modern threat actors to hide from defenders with as seen with the emergence of Demodex used by multiple China-based threat actors to enable global espionage campaigns. This talk goes into modern rootkit capabilities in the Demodex rootkit family, and a notable overlap seen with Derusbi displaying malware tradecraft evolving over time.
About Anders Wilhelmsen
Anders Wilhelmsen is a seasoned senior threat intelligence analyst at Microsoft, focusing on discovery and emerging tradecraft from threats from south east Asia. Anders enjoys malware/tools reverse engineering to supercharge his threat intelligence work to uncover new threats.
Anders' previous experience include network analysis, incident response, threat intelligence and reverse engineering work for the Norwegian government.
