Janicab is a multi-platform espionage malware family active since at least 2013, with Windows and macOS variants, and later closely associated with the DeathStalker threat actor. It has been used against legal, financial, and travel-related organizations, including legal entities in the Middle East and victims in Europe. Janicab supports remote command execution and surveillance functions including screenshot capture, and older variants also supported audio recording. Later Windows intrusions used a VBScript-based final-stage implant and auxiliary components for keylogging, proxying, local FTP access, reverse tunneling, persistence, anti-virtual-machine checks, and downloading additional tools.
Janicab has used multi-stage infection chains. Early Windows activity included malicious Office documents exploiting CVE-2012-0158 to drop a DLL that launched an encoded Visual Basic script. Later campaigns used spearphishing with ZIP archives containing malicious shortcut droppers that launched chained VBE/VBS stages and unpacked additional resources. macOS variants used compiled Python scripts and established persistence through cron, while Windows variants established persistence through startup mechanisms and, in some cases, Winlogon shell modification.
A notable characteristic of Janicab is its use of dead-drop resolvers on public web services to obtain command-and-control information, including long-observed use of platforms such as YouTube. Some variants were signed to reduce security friction on macOS. Operationally, Janicab has overlapped with other DeathStalker toolsets through shared tradecraft and supporting utilities. High-confidence capabilities include screenshot collection with exfiltration to command-and-control infrastructure, audio capture in older variants, persistence, command execution, keylogging support through bundled components, and post-compromise access enablement through proxying and tunneling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
One of them is called ActiveX.bin and it carries the main shell-code that is triggered by a widely spread exploit CVE-2012-0158 (under special settings ActiveX controls in MSCOMCTL.OCX trigger code execution). | As a script template implicitly works a Windows version of Janicab... Janicab/StarterScreenShots.pyc ... MacOs:Janicab-D [Trj] ... Encoded VB Script ... VBS:Janicab-A [Trj] ... Win32:Janicab-A [Drp]
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
While hunting for less common Deathstalker intrusions that use the Janicab malware family, we identified a new Janicab variant used in targeting legal entities in the Middle East throughout 2020... Janicab is a VBS-based malware implant...
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence is achieved by adding an initial malicious script "runner.pyc" into cron
Function runCmd(cmd, cmdType) Function facilitating command execution using CMD.exe or PowerShell.exe
Function runCmd(cmd, cmdType) Function facilitating command execution using CMD.exe or PowerShell.exe
The Windows version has a VBscript-based implant as the final stage... The LNK file has an embedded “Command Line Arguments” field that aims at extracting and executing an encoded VBScript loader (1.VBE).
The new Janicab variants also embed a CAB archive containing several Python files and other artifacts used later in the intrusion lifecycle.
Persistence is achieved by adding an initial malicious script "runner.pyc" into cron
Persistence is achieved by adding an initial malicious script "runner.pyc" into cron
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
K.dll Named Stormwind... it’s a DLL-based keylogger... sets a global hook to capture keystrokes.
The content is a MITRE ATT&CK-style listing of malware and threat actors that "can capture screenshots," "take screenshots," "perform screen captures," or "watch the victim's screen." It ends with references to "CopyFromScreen" and "xwd."
The protocol in use for C2 communication is HTTP with GET/POST methods, and the backend C2 software is PHP.
PythonProxy.py An IPv4/IPv6 capable Python-based proxy that is able to relay web traffic between the local target system and remote C2 server.
the threat actor continues to use YouTube, Google+, and WordPress web services as DDRs.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware/campaign associated with DeathStalker, mentioned as part of the actor’s malicious activities.
Cross-platform (macOS/Windows) malware family; new variant observed in DeathStalker intrusions with a VBS-based final-stage implant and embedded/obfuscated tooling in the dropper.
Backdoor malware that captures screenshots and exfiltrates them to C2.
A modular VBS-based malware implant used by Deathstalker that provides persistence, command execution, file download, anti-analysis checks, keylogging, screenshot capture, and C2 communications via HTTP after resolving backend IPs through YouTube and other dead-drop resolvers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.