Last seven days
- First activity
- Jul 21, 2026
- Last activity
- Jul 21, 2026
- Feed role
- Distribution
- Host form
- 1 IP / 0 hostnames
Adwind is a Java-based remote access trojan (RAT), also referred to in the provided content by aliases including AlienSpy, Frutas, jBiFrost, jFrutas, jRAT, jSocket, Sockrat, Trojan.Maljava, and Unrecom.
Profile source: Mallory opens in a new tabjRAT
Adwind is a Java-based remote access trojan (RAT), also referred to in the provided content by aliases including AlienSpy, Frutas, jBiFrost, jFrutas, jRAT, jSocket, Sockrat, Trojan.Maljava, and Unrecom. The content specifically associates jRAT behaviors with Adwind and describes it as a cross-campaign RAT used for remote access, reconnaissance, credential theft, and follow-on payload delivery.
Capabilities directly mentioned in the content include mapping UPnP ports; enumerating installed security software and firewall details via WMIC/WMI; capturing clipboard data; capturing video from a webcam; supporting RDP control; stealing passwords from common web browsers including Internet Explorer, Google Chrome, and Firefox; and stealing passwords from chat applications including MSN Messenger, AOL Instant Messenger, and Google Talk. The content also notes distribution as HTA files with JScript.
Adwind has been observed in multiple criminal contexts. Proofpoint linked infrastructure associated with TA2722/Balikbayan Foxes to a registration email, anthony.marshall.1986@gmail[.]com, that had previously been associated with Adwind RAT campaigns reported in 2017. Separately, Unit 42 listed Adwind among the top RAT families used in Nigerian BEC scams.
The most detailed recent reporting in the content concerns a customized Adwind variant used by an Acronis-tracked threat cluster to deliver the JanaWare ransomware family. In that campaign, phishing emails delivered malicious Java archive files, including cases where Outlook launched Chrome to open a Google Drive link that downloaded a malicious JAR executed via javaw.exe. The customized Adwind variant was heavily obfuscated using Stringer and Allatori, used custom class loaders, and included a FilePumper component that modified its own JAR by adding random content, producing polymorphic samples with different hashes. The malware embedded hard-coded configuration including a C2 domain, TCP ports, Tor-related paths, a version identifier, startup/persistence settings, and a static PASSWORD value used both for initial authentication and payload decryption.
In the JanaWare activity, Adwind acted as a multi-stage loader and enforced geofencing based on Turkish language, locale, country settings, and external IP geolocation, proceeding only when the environment matched Turkey. After those checks, it executed PowerShell and registry commands to weaken defenses, including attempts to disable or weaken Microsoft Defender, suppress security notifications, remove Volume Shadow Copy recovery mechanisms, hide ransomware protection features, enumerate installed antivirus products, and interfere with endpoint protection integrations. It then downloaded a Java ransomware plugin that communicated over Tor, encrypted files across available drives using AES, and dropped Turkish-language ransom notes with partially randomized filenames containing the fixed prefix _ONEMLI_NOT_. Victimology in that campaign was described as primarily Turkish home users and small to medium-sized businesses, with observed ransom demands of roughly $200 to $400. The content identifies sample hash 4f0444e11633a331eddb0deeec17fd69 as Adwind RAT and infrastructure at elementsplugin.duckdns.org resolving to 151.243.109.115 on ports 49152 and 49153.
Samples
Reported operators
The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.