Adwind is a commercially available, cross-platform Java remote access trojan that has circulated under multiple names including AlienSpy, jRAT, JSocket, Frutas, Unrecom, and Sockrat. It is designed to run wherever a Java Runtime Environment is present and has been observed targeting Windows, Linux, and macOS systems, with some reporting also noting BSD and Solaris compatibility. Adwind has been used in both broad criminal spam operations and targeted spearphishing campaigns, including activity against financial organizations and politically connected targets.
Adwind provides full remote administration and surveillance capabilities. Documented functions include process listing and termination, command execution, screenshot capture, keylogging, browser password theft, theft of credentials from chat applications, collection of internal and external IP address information, file deletion, and discovery of installed security software such as antivirus and firewall products. Campaign reporting has also associated Adwind with webcam access, file transfer, shell access, registry editing, reverse proxying, and persistence mechanisms. Some variants employ heavy obfuscation, encrypted resources, staged class loading, and self-update logic to hinder analysis and maintain operator control.
Observed delivery methods include phishing and spearphishing emails, malicious Java archive payloads, HTA-based delivery using JScript or VBScript, and spam campaigns using weaponized document workflows. Public reporting has described lures themed as shipping notices, invoices, payment details, fake software updates, and Excel-compatible attachments abusing Dynamic Data Exchange to retrieve and execute the Java payload. Adwind has also appeared in campaigns targeting Indian co-operative banks and finance companies, and in Operation Manul, which used commodity RATs against Kazakh dissidents, journalists, lawyers, and associates.
Adwind is notable for its long operational lifespan, broad alias set, and adaptability across intrusion types ranging from commodity cybercrime to targeted surveillance. Its Java implementation and cross-platform design made it especially attractive to operators seeking a single RAT family capable of infecting diverse desktop environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The malicious spam messages were crafted to exploit CVE-2017-11882. The remote code execution flaw is specific to Microsoft Word Equation Editor. Once exploited, the Warzone RAT payload is downloaded and installed.
In some cases, the infrastructure used is the same as the one we saw when analyzing the Adwind Trojan.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The top 10 of the RATs used in Nigerian BEC scams is formed by NetWire, DarkComet, NanoCore, LuminosityLink, Remcos, ImminentMonitor, NJRat, Quasar, Adwind, and Hworm.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
it’s obvious that it uses obfuscation technology to protect it from being easily analyzed. The package names, class names, function names, field names, and resource names are all random strings.
Phishers and scammers traditionally misuse the names of well-known organizations and individuals in order to make their malicious messages seem legitimate... The downloaded file is named “upslabels.jar”.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The covered campaigns have primarily been engineered for credential harvesting. Some utilize commodity malware, where others simply redirect to weaponized phishing sites.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine... Agent Tesla has the ability to extract credentials from configuration or support files... APT33 has used a variety of publicly available tools like LaZagne to gather credentials.
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
The covered campaigns have primarily been engineered for credential harvesting. Some utilize commodity malware, where others simply redirect to weaponized phishing sites.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Over the last six years there has been an increased shift by malware authors to secure their C&C communications using the SSL/TLS protocol to stymie detection and blend in with normal traffic.
160 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
99 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan used in COVID-themed phishing campaigns.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
Java-based remote access trojan repurposed in this campaign as a multi-stage loader delivering JanaWare, with added modules and post-exploitation scripts.
A customized Java-based remote access trojan used as the initial payload in the JanaWare campaign. It is delivered via phishing and malicious JAR files, establishes a foothold, uses obfuscation and polymorphism, and deploys the ransomware module after confirming the victim is in Turkey.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.