Brambul
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In October 2015, Symantec found evidence that organizations in South Korea were being targeted by a number of malicious tools, including Backdoor.Duuzer, W32.Brambul, and Backdoor.Joanap.
Brambul malware is a brute-force authentication worm that spreads through SMB shares.
Techniques & procedures
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
The Justice Department today announced an extensive effort to map and further disrupt, through victim notifications, the Joanap botnet – a global network of numerous infected computers under the control of North Korean hackers... Computers infected with Joanap — known as “peers” or “bots” — became part of a network of compromised computers known as a botnet.
Credential Access
2 techniques
Credential Access
Discovery
2 techniques
Discovery
Lateral Movement
4 techniques
Lateral Movement
HIDDEN COBRA actors can use this information to remotely access a compromised system via the SMB protocol.
Brambul malware is a brute-force authentication worm that spreads through SMB shares.
Collection
1 technique
Collection
Command and Control
1 technique
Command and Control
Joanap is a “second stage” malware, one that is often “dropped” by the automated Brambul “worm”... Once installed on an infected computer, Joanap would allow the North Korean hackers to remotely access infected computers... and load additional malware onto infected computers.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows 32-bit SMB worm that spreads laterally in victim networks over SMB, performs brute-force password attacks, and reports victim details to operators via email for follow-on remote operations.
A first-stage worm used to propagate Joanap and gain unauthorized access to computers by crawling from system to system and probing for access via certain vulnerabilities.
A malicious Windows 32-bit SMB worm that spreads via SMB shares by using embedded credentials to brute-force access over ports 139 and 445. It harvests system information, propagates laterally, and sends victim host details and credentials to operators via email.
Malicious tool used in Lazarus-attributed espionage activity targeting South Korean manufacturing organizations.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.