s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.janicab

📛 Threat Title

Malware family: Janicab

Category: Janicab First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.janicab`. Printable name: Janicab.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.janicab VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.janicab

IOC database

Type
domain
Value
osx.janicab
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.janicab

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.janicab

References (1)

Remediations (10)

  • web:attack.mitre.org

    Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019. Remillano, A., Urbanec, J. (2019, September 19). Skidmap Linux Malware Uses Rootkit Capabilities to Hide Cryptocurrency-Mining Payload. Retrieved June 4, 2020. Check Point Research. (2019, February 4). SpeakUp: A New Undetected Backdoor Linux Trojan.

  • web:cybernoz.com

    Janicab infections can lead to targeted logistical and legal issues, competitive advantage for rivals, unexpected audits with bias, and misuse of intellectual property, rather than traditional cyberattack consequences like ransomware or digital extortion.

  • web:malpedia.caad.fkie.fraunhofer.de

    Janicab Propose Change Actor (s): Evilnum According to Patrick Wardle, this malware persists a python script as a cron job. Steps: 1. Python installer first saves any existing cron jobs into a temporary file named '/tmp/dump'. 2. Appends its new job to this file. 3. Once the new cron job has been added 'python (~/.t/runner.pyc)' runs every minute.

  • web:securityaffairs.com

    The threat actors employed a new variant of the Janicab malware that relies on public services like WordPress and YouTube as dead drop resolvers. The researchers spotted the new variant while investigating Evilnum (aka Deathstalker) intrusions that use the Janicab malware family .

  • web:technologydispatch.com

    Janicab can be considered a modular, interpreted-language malware , which means that the threat actor is able to add/remove functions or embedded files with very little effort. Based on Kaspersky telemetry - even though the delivery mechanism remains spear-phishing - newer Janicab variants have changed significantly in structure, with the presence of archives containing several Python files ...

  • web:thecyberexpress.com

    New Janicab malware can lead to targeted logistical and legal issues, competitive advantage for rivals, unexpected audits with bias, and misuse of intellectual property.

  • web:www.kaspersky.co.uk

    Kaspersky experts have identified new functionalities within the Janicab malware , which is being used by a mercenary APT group DeathStalker to infiltrate specific organisations within a number of industries.

  • web:www.linkedin.com

    This research-driven analysis explores the potential attack vectors, malware families, real-world Jamaican use cases, and most importantly, mitigation strategies.

  • web:www.redpacketsecurity.com

    Just to clarify, the above subheading isn't a normal quote, but a message that Janicab malware attempted to decode in its newest use of YouTube dead-drop resolvers (DDRs). While hunting for less common Deathstalker intrusions that use the Janicab malware family , we identified a new Janicab variant used in targeting legal entities in the Middle East throughout 2020, possibly active during ...

  • web:www.scworld.com

    Hack-for-hire threat group Evilnum, also known as DeathStalker, has been deploying an updated variant of the Janicab malware in its attacks against travel agencies, financial investment organizations, and legal firms in Georgia, Egypt, Saudi Arabia, the United Arab Emirates, and the U.K., in an effort to exfiltrate corporate information, reports The Hacker News.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.