Also known as: AlienSpy, JSocket, Frutas, UNRECOM, JBifrost, Sockrat
No AI analysis yet.
Part of Malware-as-service platform Used as a generic name for Java-based RAT Functionality - collect general system and user information - terminate process -log keystroke -take screenshot and access webcam - steal cache password from local or web forms - download and execute Malware - modify registry - download components - Denial of Service attacks - Acquire VPN certificates Initial infection vector 1. Email to JAR files attached 2. Malspam URL to downlaod the malware Persistence - Runkey - HKCU\Software\Microsoft\Windows\current version\run Hiding Uses attrib.exe Notes on Adwind The malware is not known to be proxy aware