Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lookout researchers are monitoring the evolution of an Android surveillanceware family known as JadeRAT... Emerging in 2015 and becoming increasingly active, JadeRAT provides its operators with a significant degree of control over a compromised device and supports over 60 commands that are focused on retrieving sensitive information and profiling victims.
Lookout researchers are monitoring the evolution of an Android surveillanceware family known as JadeRAT... Emerging in 2015 and becoming increasingly active, JadeRAT provides its operators with a significant degree of control over a compromised device and supports over 60 commands that are focused on retrieving sensitive information and profiling victims.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
JadeRAT provides its operators with a significant degree of control over a compromised device and supports over 60 commands that are focused on retrieving sensitive information and profiling victims.
As JadeRAT simply opens up a socket to a specified address and uses quite a basic instruction format without any authentication... Production releases rarely reuse domains or IP addresses, frequently use dynamic DNS, and communicate on various non-standard ports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android surveillanceware/RAT that gives operators extensive control over infected devices, including data theft, call and SMS interception, audio recording, screenshot capture, location tracking, file operations, command execution with root, and exfiltration of chat data such as MicroMsg and QQ media/databases.
Android RAT used in a separate but overlapping campaign targeting the Uyghur community.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.