TF-MAL-osx.janicab
📛 Threat Title
Malware family: Janicab
Description
ThreatFox malware family `osx.janicab`. Printable name: Janicab.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.janicab
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.janicab
IOC database
- Type
- domain
- Value
osx.janicab- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.janicab
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.janicab
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019. Remillano, A., Urbanec, J. (2019, September 19). Skidmap Linux Malware Uses Rootkit Capabilities to Hide Cryptocurrency-Mining Payload. Retrieved June 4, 2020. Check Point Research. (2019, February 4). SpeakUp: A New Undetected Backdoor Linux Trojan.
-
web:cybernoz.com
Janicab infections can lead to targeted logistical and legal issues, competitive advantage for rivals, unexpected audits with bias, and misuse of intellectual property, rather than traditional cyberattack consequences like ransomware or digital extortion.
-
web:malpedia.caad.fkie.fraunhofer.de
Janicab Propose Change Actor (s): Evilnum According to Patrick Wardle, this malware persists a python script as a cron job. Steps: 1. Python installer first saves any existing cron jobs into a temporary file named '/tmp/dump'. 2. Appends its new job to this file. 3. Once the new cron job has been added 'python (~/.t/runner.pyc)' runs every minute.
-
web:securityaffairs.com
The threat actors employed a new variant of the Janicab malware that relies on public services like WordPress and YouTube as dead drop resolvers. The researchers spotted the new variant while investigating Evilnum (aka Deathstalker) intrusions that use the Janicab malware family .
-
web:technologydispatch.com
Janicab can be considered a modular, interpreted-language malware , which means that the threat actor is able to add/remove functions or embedded files with very little effort. Based on Kaspersky telemetry - even though the delivery mechanism remains spear-phishing - newer Janicab variants have changed significantly in structure, with the presence of archives containing several Python files ...
-
web:thecyberexpress.com
New Janicab malware can lead to targeted logistical and legal issues, competitive advantage for rivals, unexpected audits with bias, and misuse of intellectual property.
-
web:www.kaspersky.co.uk
Kaspersky experts have identified new functionalities within the Janicab malware , which is being used by a mercenary APT group DeathStalker to infiltrate specific organisations within a number of industries.
-
web:www.linkedin.com
This research-driven analysis explores the potential attack vectors, malware families, real-world Jamaican use cases, and most importantly, mitigation strategies.
-
web:www.redpacketsecurity.com
Just to clarify, the above subheading isn't a normal quote, but a message that Janicab malware attempted to decode in its newest use of YouTube dead-drop resolvers (DDRs). While hunting for less common Deathstalker intrusions that use the Janicab malware family , we identified a new Janicab variant used in targeting legal entities in the Middle East throughout 2020, possibly active during ...
-
web:www.scworld.com
Hack-for-hire threat group Evilnum, also known as DeathStalker, has been deploying an updated variant of the Janicab malware in its attacks against travel agencies, financial investment organizations, and legal firms in Georgia, Egypt, Saudi Arabia, the United Arab Emirates, and the U.K., in an effort to exfiltrate corporate information, reports The Hacker News.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.