Also known as: Project Spy, Cridex, U2DiskWatch, similar to Sliver, Cobalt Strike, consists of multiple components, control module, NoFive, Plat1
JavaGhost is a long‑active threat actor that specializes in abusing cloud environments—particularly Amazon Web Services—to conduct credential stuffing and mass phishing campaigns. By exploiting overly permissive IAM policies, the group can send emails through AWS SES and WorkMail services using compromised or newly created roles, often without leaving a trace on the affected infrastructure beyond CloudTrail logs. Their techniques deliberately avoid calling GetCallerIdentity, minimizing detection by standard cloud monitoring tooling. In addition to cloud‑centric operations, JavaGhost also employs USB‑borne vectors, deploying malicious LNK shortcuts that download remote payloads and inject backdoors into native processes. Once inside a victim system, the malware can use tools like Cobalt Strike, Pikabot, or custom loaders (e.g., HUI Loader, Squirrelwaffle) to maintain persistence, expand lateral movement, and optionally deploy ransomware. The actor’s arsenal combines social engineering, credential dumping through tools such as Mimikatz and T6003.001, exploitation of public vulnerabilities (for example CVE‑2024‑3400 in Palo Alto firewalls), and sophisticated encoding or encryption to evade endpoint detection. While JavaGhost does not appear to engage in data exfiltration for extortion within the cloud environment, it leverages other organizations’ infrastructure to avoid costs, suggesting a focus on broad reach over deeper compromise. Overall, JavaGhost represents a hybrid threat model: cloud‑based phishing and lateral movement merged with traditional endpoint exploitation techniques, enabling highly scalable attacks across multiple sectors worldwide.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
JavaGhost is a stealthy actor that exploits overly permissive AWS IAM roles to launch large‐scale phishing campaigns from compromised cloud accounts. It delivers malware via infected USB LNK objects and spam emails while leveraging native process injection for persistence, with an apparent focus on financial gain rather than extortion. The group’s operations span dozens of industries and countries, raising concerns about widespread IAM abuse in the cloud.
Goals & Targeting
JavaGhost’s primary objective is monetary gain through the distribution of ransomware or extortionary payloads at scale. By targeting cloud services for initial access, it reduces operational costs and obfuscates its footprint, making attribution difficult. The actor selects a diverse set of industries—financial services, defense, healthcare, energy, and retail—to maximize impact while exploiting common IAM misconfigurations. While no extortion was observed in cloud environments, the widespread deployment signals an intent to harvest credentials, install backdoors, and prepare for later lateral movement or direct data exfiltration. The group’s geographic spread—from North America and Europe to Asia and the Middle East—indicates a broad targeting strategy that aligns with state sponsorship patterns. The focus on privileged IAM roles and cloud email services showcases a strategic preference for high‑value, low‑effort attack vectors that can be replicated across many organizations simultaneously.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
JavaGhost has exhibited a pattern of rapid, multi‑sector operations characterized by the exploitation of cloud IAM misconfigurations followed by lateral spread via USB devices and phishing emails. The actor typically operates at a high tempo, deploying hundreds of campaigns within weeks and targeting both public and private sector victims across North America, Europe and Asia. Victims are often chosen based on the presence of permissive S3, SES or WorkMail roles, with no discernible focus beyond maximizing compromised account volume. Notable past operations include phishing campaigns that leveraged malicious LNK files to install backdoors, exploitation of a Palo Alto firewall CVE to gain network footholds, and the use of the T9000 tool for system reconnaissance against U.S. organizations. While detailed attribution remains uncertain, many indicators align with state‑sponsored capabilities from China (PRC), including advanced evasion techniques, code obfuscation, and reuse of tools seen in other PRC groups (e.g., Pikabot, Raspberry Robin). The attacker’s strategy appears more opportunistic (scoring credential access) than targeted espionage. Overall, the campaign structure is modular: initial cloud exploitation → phishing via SES/WorkMail or USB LNK delivery → installation of backdoors/loader payloads → optional ransomware deployment or data exfiltration. This framework allows JavaGhost to scale attacks without raising immediate suspicion across multiple sectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information regarding IAM privilege abuse, phishing via SES/WorkMail and malicious LNK delivery is drawn from multiple independent observations and provides a moderate to high confidence assessment of JavaGhost’s operational patterns. However, attribution to a specific nation‑state remains speculative; gaps persist around detailed persistence mechanisms beyond process injection and the full extent of their use of state‑grade malware families. Overall, the data supports actionable defensive guidance but further monitoring is required for complete contextual coverage.
No campaigns linked yet.
No observed data linked yet.
14
Techniques
51
Tools
0
Campaigns
40
IOCs
0
Observed Data
8
Tactics