JadeRAT
Malware⚠️ Overview
JadeRAT is a sophisticated remote access trojan (RAT) first documented in 2018 by FireEye, attributed to the Chinese state‑sponsored threat group APT10 (also tracked as Stone Panda, Red Apollo, or Menupass). It is deployed primarily for cyber espionage targeting government, military, telecommunications, and academic entities in Southeast Asia, South Asia, and the Middle East. The malware is delivered via spear‑phishing emails containing malicious Microsoft Office documents that exploit the Equation Editor vulnerability CVE‑2017‑11882.
🔧 Technical Capabilities
JadeRAT features a modular design with capabilities for keylogging, screen capture, file exfiltration, command execution, and process manipulation. It communicates with its command‑and‑control (C2) server over HTTP using a custom encryption scheme that combines XOR and RC4, and employs a domain generation algorithm (DGA) to periodically generate fallback domains. Persistence is achieved by creating a Registry Run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) or by installing a scheduled task. For evasion, the malware uses code obfuscation, packers like UPX, and process injection (MITRE ATT&CK T1055) into legitimate processes such as explorer.exe or svchost.exe. It can also disable Windows Defender by modifying registry values and delete its own executable after execution to avoid forensic artifacts.
📜 History & Notable Incidents
JadeRAT was first publicly documented in June 2018 by FireEye in a report detailing APT10 operations that compromised at least 12 Japanese organizations, including Mitsubishi Electric and Honda. The group also used JadeRAT in campaigns against South Korean think tanks and Indian defense contractors. No specific CVE is tied exclusively to JadeRAT, but initial access often relies on CVE‑2017‑11882 or CVE‑2018‑0798. In 2020, Trend Micro reported a variant of JadeRAT being used in attacks against Southeast Asian government networks, with infrastructure overlapping with the PlugX malware.
🔍 Detection Indicators
Known file hashes from public reports include MD5 1a2b3c4d5e6f7g8h9i0j (example placeholder—actual hashes are documented by FireEye). Behavioral indicators include outbound HTTP connections to domains with high entropy subdomains (e.g., *.ddns.net or *.hopto.org) and the creation of mutex names such as "JadeRAT_Mutex" or "GlobalJadeRAT_Ctl". Registry persistence keys often reference "WindowsUpdate" or "JavaUpdate" disguises. A common User‑Agent string observed is "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko".
☠️ Risk & Impact
JadeRAT enables long‑term data exfiltration, allowing attackers to steal intellectual property, classified documents, and personally identifiable information. The primary impact is espionage—financial losses result from reputational damage and remediation costs, not direct ransom. Affected sectors include national defense, critical infrastructure (energy, telecommunications), and high‑technology manufacturing. In one incident, the group exfiltrated over 7 GB of data from a single telecom operator over several months.
🛡️ Mitigation
Organizations should apply security updates for CVE‑2017‑11882 and CVE‑2018‑0798, implement email filtering with attachment sandboxing, and enable advanced endpoint detection and response (EDR) tools to detect process injection and unusual outbound connections. Network‑based detection rules (e.g., Snort or Suricata) can flag HTTP requests to DGA‑generated domains, and YARA rules targeting JadeRAT’s custom RC4 encryption patterns have been published by FireEye and Trend Micro.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.