Jaku Botnet Rises in the East

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
A previously unknown botnet has been uncovered, built for a multi-stage tracking and data exfiltration, primarily of targets in Asia.

According to Forcepoint’s 2016 Global Threat Report, Jaku has claimed 19,000 victims across 134 countries so far.

"Jaku herds victims en masse and conducts highly targeted attacks on specific victims through the execution of concurrent operational campaigns," it explained.

Technical details are still forthcoming in May from the firm, but it did say that payloads are delivered via exposure to compromised BitTorrent sites, the use of unlicensed software and the downloading of the Warez software. It also uses a raft of evasion techniques, like cryptography, steganography, fake file types, stealth injection, antivirus engine detection and more.

Forcepoint said that the victims are located around the globe, but there’s significant clustering in Asia, especially Japan, South Korea and China. The command and control servers are located in Malaysia, Thailand and Singapore.

Jaku was discovered as a result of a six-month investigation by Forcepoint’s Special Investigations (SI) team, as detailed in the company’s report. It worked with Kaspersky, using that firm’s analysis of the Dark Hotel campaign, as well as the UK National Crime Agency (NCA), CERT-UK, Europol and Interpol.

Full Article. Jaku Botnet Rises in the East
 

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
Good thing I don't torrent.
I know how it works though and with the "seeding" process I bet it would be easy to spread malware from PC to PC rapidly.
Nice share Frog.
PeAcE
 
  • Like
Reactions: LabZero and frogboy

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top