The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.
jRAT
Adwind is a commercially available, cross-platform Java remote access trojan that has circulated under multiple names including AlienSpy, jRAT, JSocket, Frutas, Unrecom, and Sockrat.
Profile source: Mallory opens in a new tabjRAT
Family profile
Adwind is a commercially available, cross-platform Java remote access trojan that has circulated under multiple names including AlienSpy, jRAT, JSocket, Frutas, Unrecom, and Sockrat. It is designed to run wherever a Java Runtime Environment is present and has been observed targeting Windows, Linux, and macOS systems, with some reporting also noting BSD and Solaris compatibility. Adwind has been used in both broad criminal spam operations and targeted spearphishing campaigns, including activity against financial organizations and politically connected targets.
Adwind provides full remote administration and surveillance capabilities. Documented functions include process listing and termination, command execution, screenshot capture, keylogging, browser password theft, theft of credentials from chat applications, collection of internal and external IP address information, file deletion, and discovery of installed security software such as antivirus and firewall products. Campaign reporting has also associated Adwind with webcam access, file transfer, shell access, registry editing, reverse proxying, and persistence mechanisms. Some variants employ heavy obfuscation, encrypted resources, staged class loading, and self-update logic to hinder analysis and maintain operator control.
Observed delivery methods include phishing and spearphishing emails, malicious Java archive payloads, HTA-based delivery using JScript or VBScript, and spam campaigns using weaponized document workflows. Public reporting has described lures themed as shipping notices, invoices, payment details, fake software updates, and Excel-compatible attachments abusing Dynamic Data Exchange to retrieve and execute the Java payload. Adwind has also appeared in campaigns targeting Indian co-operative banks and finance companies, and in Operation Manul, which used commodity RATs against Kazakh dissidents, journalists, lawyers, and associates.
Adwind is notable for its long operational lifespan, broad alias set, and adaptability across intrusion types ranging from commodity cybercrime to targeted surveillance. Its Java implementation and cross-platform design made it especially attractive to operators seeking a single RAT family capable of infecting diverse desktop environments.
Capabilities
- Credential Theft
- Defense Evasion
- Keylogging
- Persistence
- Post Exploitation
- Reconnaissance
Reported operators
Threat actors
1 named in public reportingExploited software
Vulnerabilities linked to jRAT
2 CVEsMITRE ATT&CK
jRAT in ATT&CK
62 distinct techniquesTechniques
62 techniquesReporting
Research mentioning jRAT
Post by @lazarusholic.bsky.social - Bluesky
A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.
Detection: Cmdline Tool Not Executed In CMD Shell | Splunk Security Content
Detect Credential Access with Elastic Security | Elastic Security Labs
Elastic Endpoint Security added kernel-driver-derived file and registry telemetry to detect access to sensitive credential stores, including browser data, Windows SAM and LSA secrets, cached domain credentials, credential files, and Windows Credential Manager. Its behavior protections can block high-confidence credential-theft activity associated with tools and malware such as Mimikatz, LaZagne, AgentTesla, FormBook, and Poulight Stealer; KQL and EQL hunting can also identify processes opening multiple sensitive stores or SMB access following a network logon. Attackers commonly extract saved browser usernames, passwords, cookies, and session tokens from stores such as Chrome’s Login Data and Firefox’s key3.db, key4.db, and logins.json. They also dump Windows LSA secrets and cached domain credentials using utilities including Mimikatz, reg save, Impacket secretsdump.py, CrackMapExec, and gsecdump. Cached Windows credentials are generally stored as DCC2/MS-Cache v2 hashes and require offline cracking rather than pass-the-hash, while Linux Active Directory integrations may retain cached credentials in SSSD or Quest database files.
Man jailed for using webcam RAT to spy on women in their bedrooms
An international law enforcement operation disrupted the Imminent Monitor remote access trojan (RAT), a malware tool marketed online as legitimate remote administration software but widely used for cybercrime. Researchers at Palo Alto Networks Unit 42 said they collected more than 65,000 samples and observed over 115,000 attacks tied to the malware, which included stealth and persistence features, antivirus-evasion tooling, hidden keylogging, and later cryptocurrency-mining capability. Investigators linked the malware’s developer, known as "Shockwave™", to Australia and referred the case to the Australian Federal Police, which worked with partners including the FBI and Canada’s CRTC to support Operation Cepheus and disable the RAT’s licensing infrastructure. The takedown exposed purchaser records and triggered enforcement against suspected users, with authorities reporting 85 warrants, 434 device seizures, and 13 arrests. In the UK, that investigation led to the conviction of Scott Cowley of St Helens, Merseyside, who was sentenced to two years in prison after forensic analysis found he had used Imminent Monitor to hijack the webcams of three women and secretly record them in their bedrooms. The case underscored how a commodity RAT sold to thousands of customers was used not only for intrusion and surveillance, but also for sexual abuse and other criminal activity.
Cyble - BianLian: New Ransomware Variant On The Rise
BianLian emerged as a Go-based ransomware family targeting organizations in manufacturing, education, healthcare, and BFSI, with victims reporting file encryption and double-extortion threats. The malware appends the .bianlian extension to encrypted files, drops a ransom note named "Look at this instruction.txt", and warns that allegedly stolen financial, client, business, technical, and personal data will be leaked within ten days unless payment is made through negotiations conducted over TOX Messenger and a Tor-based leak site. Technical analysis shows the malware was built to hinder detection and speed impact on victim systems. BianLian performs anti-analysis checks associated with MITRE ATT&CK T1497 virtualization and sandbox evasion, creates multiple threads to accelerate encryption, enumerates drives from A: through Z:, excludes selected files and folders from encryption, and deletes itself after execution. Its behavior also aligns with broader defense-evasion patterns such as executable obfuscation and packing captured in MITRE ATT&CK T1027.002, underscoring how the ransomware combines rapid file encryption with techniques intended to frustrate automated analysis and reverse engineering.
Bandidos at large: A spying campaign in Latin America
A long-running cyberespionage operation dubbed Bandidos used the Bandook remote access trojan to infiltrate corporate networks across Spanish-speaking Latin America, with roughly 90% of observed detections concentrated in Venezuela. The campaign, active since at least 2015, relied on phishing emails carrying PDF lures that directed victims to password-protected archives containing a Delphi dropper. That dropper injected Bandook into iexplore.exe through process hollowing, established persistence via Windows Registry changes, and connected to command-and-control servers over TCP. Researchers said the malware supported extensive surveillance and theft functions, including screenshot capture, webcam and microphone recording, USB data theft, and interception of Chrome credentials, while also downloading additional DLLs to expand capability. The 2021 variant showed notable evolution from earlier Bandook activity, including a shift from CAST-256 to GOST in the dropper, a reduced DLL set, and support for 132 commands. The infrastructure and tooling overlapped with previously documented Bandook-linked operations, including Operation Manul, Dark Caracal, and Check Point research, reinforcing the assessment that the operators were conducting sustained espionage against Venezuelan organizations in sectors such as manufacturing, construction, healthcare, software services, and retail.
KryptoCibule: The multitasking multicurrency cryptostealer
ESET disclosed KryptoCibule, a previously undocumented malware family active since at least late 2018 that primarily targeted users in Czechia and Slovakia through malicious torrents posing as cracked software installers. The malware combined several cryptocurrency-focused functions: it mined coins on infected systems, monitored the clipboard to replace copied wallet addresses and redirect payments, searched for cryptocurrency wallets and related files for exfiltration, and also exposed remote-access trojan (RAT) capabilities. The campaign relied heavily on Tor and BitTorrent infrastructure and either bundled or fetched legitimate tools including Tor, Transmission, Apache httpd, and Buru SFTP Server to support command-and-control and data theft through onion services hosted on compromised machines. ESET said KryptoCibule used layered evasion and persistence measures, including obfuscation, masquerading as Adobe Reader components, scheduled tasks, Windows Defender exclusions, firewall rule changes, and checks for analysis tools and antivirus products; although only hundreds of victims were observed, the malware remained active and continued to gain new capabilities.