Skip to content

jRAT

Adwind is a commercially available, cross-platform Java remote access trojan that has circulated under multiple names including AlienSpy, jRAT, JSocket, Frutas, Unrecom, and Sockrat.

Profile source: Mallory opens in a new tab

jRAT

Family profile

Adwind is a commercially available, cross-platform Java remote access trojan that has circulated under multiple names including AlienSpy, jRAT, JSocket, Frutas, Unrecom, and Sockrat. It is designed to run wherever a Java Runtime Environment is present and has been observed targeting Windows, Linux, and macOS systems, with some reporting also noting BSD and Solaris compatibility. Adwind has been used in both broad criminal spam operations and targeted spearphishing campaigns, including activity against financial organizations and politically connected targets.

Adwind provides full remote administration and surveillance capabilities. Documented functions include process listing and termination, command execution, screenshot capture, keylogging, browser password theft, theft of credentials from chat applications, collection of internal and external IP address information, file deletion, and discovery of installed security software such as antivirus and firewall products. Campaign reporting has also associated Adwind with webcam access, file transfer, shell access, registry editing, reverse proxying, and persistence mechanisms. Some variants employ heavy obfuscation, encrypted resources, staged class loading, and self-update logic to hinder analysis and maintain operator control.

Observed delivery methods include phishing and spearphishing emails, malicious Java archive payloads, HTA-based delivery using JScript or VBScript, and spam campaigns using weaponized document workflows. Public reporting has described lures themed as shipping notices, invoices, payment details, fake software updates, and Excel-compatible attachments abusing Dynamic Data Exchange to retrieve and execute the Java payload. Adwind has also appeared in campaigns targeting Indian co-operative banks and finance companies, and in Operation Manul, which used commodity RATs against Kazakh dissidents, journalists, lawyers, and associates.

Adwind is notable for its long operational lifespan, broad alias set, and adaptability across intrusion types ranging from commodity cybercrime to targeted surveillance. Its Java implementation and cross-platform design made it especially attractive to operators seeking a single RAT family capable of infecting diverse desktop environments.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance

Reported operators

Threat actors

1 named in public reporting
SilverTerrier

The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.

Exploited software

Vulnerabilities linked to jRAT

2 CVEs

MITRE ATT&CK

jRAT in ATT&CK

62 distinct techniques

Techniques

62 techniques
T1057 Process Discovery T1555.003 Credentials from Web Browsers T1113 Screen Capture T1105 Ingress Tool Transfer T1083 File and Directory Discovery T1082 System Information Discovery T1555 Credentials from Password Stores T1056.001 Keylogging T1518.001 Security Software Discovery T1059.007 JavaScript T1016 System Network Configuration Discovery T1056 Input Capture T1059.003 Windows Command Shell T1059.005 Visual Basic T1070.004 File Deletion T1566 Phishing T1620 Reflective Code Loading T1547.001 Registry Run Keys / Startup Folder T1027 Obfuscated Files or Information T1071 Application Layer Protocol T1140 Deobfuscate/Decode Files or Information T1036 Masquerading T1505.003 Web Shell T1005 Data from Local System T1219 Remote Access Tools T1018 Remote System Discovery T1125 Video Capture T1112 Modify Registry T1190 Exploit Public-Facing Application T1485 Data Destruction T1204 User Execution T1566.001 Spearphishing Attachment T1529 System Shutdown/Reboot T1047 Windows Management Instrumentation T1059 Command and Scripting Interpreter T1497 Virtualization/Sandbox Evasion T1568 Dynamic Resolution T1189 Drive-by Compromise T1498 Network Denial of Service T1090 Proxy T1566.002 Spearphishing Link T1120 Peripheral Device Discovery T1115 Clipboard Data T1518 Software Discovery T1657 Financial Theft T1021.001 Remote Desktop Protocol T1204.002 Malicious File T1027.002 Software Packing T1497.001 System Checks T1053 Scheduled Task/Job T1552.004 Private Keys T1007 System Service Discovery T1053.005 Scheduled Task T1090.001 Internal Proxy T1552.001 Credentials In Files T1123 Audio Capture T1029 Scheduled Transfer T1568.003 DNS Calculation T1090.004 Domain Fronting T1049 System Network Connections Discovery T1037.005 Startup Items T1218.005 Mshta

Reporting

Research mentioning jRAT

Aug 11
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.

May 13
Splunk Research

Detection: Cmdline Tool Not Executed In CMD Shell | Splunk Security Content

Mar 1
Elastic Security Labs

Detect Credential Access with Elastic Security | Elastic Security Labs

Elastic Endpoint Security added kernel-driver-derived file and registry telemetry to detect access to sensitive credential stores, including browser data, Windows SAM and LSA secrets, cached domain credentials, credential files, and Windows Credential Manager. Its behavior protections can block high-confidence credential-theft activity associated with tools and malware such as Mimikatz, LaZagne, AgentTesla, FormBook, and Poulight Stealer; KQL and EQL hunting can also identify processes opening multiple sensitive stores or SMB access following a network logon. Attackers commonly extract saved browser usernames, passwords, cookies, and session tokens from stores such as Chrome’s Login Data and Firefox’s key3.db, key4.db, and logins.json. They also dump Windows LSA secrets and cached domain credentials using utilities including Mimikatz, reg save, Impacket secretsdump.py, CrackMapExec, and gsecdump. Cached Windows credentials are generally stored as DCC2/MS-Cache v2 hashes and require offline cracking rather than pass-the-hash, while Linux Active Directory integrations may retain cached credentials in SSSD or Quest database files.

Oct 1
Tripwire

Man jailed for using webcam RAT to spy on women in their bedrooms

An international law enforcement operation disrupted the Imminent Monitor remote access trojan (RAT), a malware tool marketed online as legitimate remote administration software but widely used for cybercrime. Researchers at Palo Alto Networks Unit 42 said they collected more than 65,000 samples and observed over 115,000 attacks tied to the malware, which included stealth and persistence features, antivirus-evasion tooling, hidden keylogging, and later cryptocurrency-mining capability. Investigators linked the malware’s developer, known as "Shockwave™", to Australia and referred the case to the Australian Federal Police, which worked with partners including the FBI and Canada’s CRTC to support Operation Cepheus and disable the RAT’s licensing infrastructure. The takedown exposed purchaser records and triggered enforcement against suspected users, with authorities reporting 85 warrants, 434 device seizures, and 13 arrests. In the UK, that investigation led to the conviction of Scott Cowley of St Helens, Merseyside, who was sentenced to two years in prison after forensic analysis found he had used Imminent Monitor to hijack the webcams of three women and secretly record them in their bedrooms. The case underscored how a commodity RAT sold to thousands of customers was used not only for intrusion and surveillance, but also for sexual abuse and other criminal activity.

Aug 18
Cyble Blog Historic

Cyble - BianLian: New Ransomware Variant On The Rise

BianLian emerged as a Go-based ransomware family targeting organizations in manufacturing, education, healthcare, and BFSI, with victims reporting file encryption and double-extortion threats. The malware appends the .bianlian extension to encrypted files, drops a ransom note named "Look at this instruction.txt", and warns that allegedly stolen financial, client, business, technical, and personal data will be leaked within ten days unless payment is made through negotiations conducted over TOX Messenger and a Tor-based leak site. Technical analysis shows the malware was built to hinder detection and speed impact on victim systems. BianLian performs anti-analysis checks associated with MITRE ATT&CK T1497 virtualization and sandbox evasion, creates multiple threads to accelerate encryption, enumerates drives from A: through Z:, excludes selected files and folders from encryption, and deletes itself after execution. Its behavior also aligns with broader defense-evasion patterns such as executable obfuscation and packing captured in MITRE ATT&CK T1027.002, underscoring how the ransomware combines rapid file encryption with techniques intended to frustrate automated analysis and reverse engineering.

Jul 7
Eset Welivesecurity

Bandidos at large: A spying campaign in Latin America

A long-running cyberespionage operation dubbed Bandidos used the Bandook remote access trojan to infiltrate corporate networks across Spanish-speaking Latin America, with roughly 90% of observed detections concentrated in Venezuela. The campaign, active since at least 2015, relied on phishing emails carrying PDF lures that directed victims to password-protected archives containing a Delphi dropper. That dropper injected Bandook into iexplore.exe through process hollowing, established persistence via Windows Registry changes, and connected to command-and-control servers over TCP. Researchers said the malware supported extensive surveillance and theft functions, including screenshot capture, webcam and microphone recording, USB data theft, and interception of Chrome credentials, while also downloading additional DLLs to expand capability. The 2021 variant showed notable evolution from earlier Bandook activity, including a shift from CAST-256 to GOST in the dropper, a reduced DLL set, and support for 132 commands. The infrastructure and tooling overlapped with previously documented Bandook-linked operations, including Operation Manul, Dark Caracal, and Check Point research, reinforcing the assessment that the operators were conducting sustained espionage against Venezuelan organizations in sectors such as manufacturing, construction, healthcare, software services, and retail.

Sep 2
Eset Welivesecurity

KryptoCibule: The multitasking multicurrency cryptostealer

ESET disclosed KryptoCibule, a previously undocumented malware family active since at least late 2018 that primarily targeted users in Czechia and Slovakia through malicious torrents posing as cracked software installers. The malware combined several cryptocurrency-focused functions: it mined coins on infected systems, monitored the clipboard to replace copied wallet addresses and redirect payments, searched for cryptocurrency wallets and related files for exfiltration, and also exposed remote-access trojan (RAT) capabilities. The campaign relied heavily on Tor and BitTorrent infrastructure and either bundled or fetched legitimate tools including Tor, Transmission, Apache httpd, and Buru SFTP Server to support command-and-control and data theft through onion services hosted on compromised machines. ESET said KryptoCibule used layered evasion and persistence measures, including obfuscation, masquerading as Adobe Reader components, scheduled tasks, Windows Defender exclusions, firewall rule changes, and checks for analysis tools and antivirus products; although only hundreds of victims were observed, the malware remained active and continued to gain new capabilities.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.