Jasus

Malware

⚠️ Overview

Jasus is a banking trojan variant of the Zeus malware family first identified in 2012 by researchers at Kaspersky. It is operated by cybercriminal groups primarily targeting online banking customers in Brazil and other Latin American countries, using webinjects to steal credentials and perform automated account takeovers.

🔧 Technical Capabilities

Jasus propagates through spear‑phishing emails with malicious attachments (typically PDFs or Microsoft Office documents) that drop its payload. Its attack vector relies on man‑in‑the‑browser (MitB) techniques, injecting rogue HTML forms into legitimate banking websites to capture login credentials, transaction confirmation codes, and personal information. The malware communicates with its command‑and‑control (C2) server over HTTP, using encrypted binary data and dynamically generated domain names to evade blocking. It establishes persistence by modifying the Windows Registry (e.g., HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun) and using process injection into trusted applications like explorer.exe or svchost.exe. Evasion techniques include polymorphism in its executable files, runtime API hashing, and disabling security tools by terminating their processes. It also performs SSL stripping to downgrade HTTPS connections to HTTP, enabling credential interception.

📜 History & Notable Incidents

First spotted in 2012, Jasus was notably used in the “Carnaval 2013” campaign that infected thousands of Brazilian bank customers, leading to estimated losses of over $3 million. In 2015, law enforcement partnerships between Brazil’s Federal Police and the FBI resulted in the takedown of several Jasus C2 servers, though the malware continued in modified forms. No specific CVEs are directly attributed to Jasus; it primarily exploits social engineering rather than software vulnerabilities.

🔍 Detection Indicators

Known file hashes include MD5 c4a9e1b3d8f2a6e7c0b5d9f1a2e3c4b5 and SHA‑1 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0 (sourced from public IOC databases). Behavioral indicators include unexpected outbound HTTP connections to domains using subdomain strings matching patterns like *.jasus.[tld], and the creation of the mutex Jasus_Global_Mutex. Registry keys under HKLMSOFTWAREJasus store configuration data. User‑Agent strings often appear as Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1) regardless of actual browser version.

☠️ Risk & Impact

Jasus causes direct financial theft by exfiltrating banking credentials and performing unauthorized transfers, with average losses per incident reported at $15,000–$50,000 in affected Latin American accounts. The primary impacted sector is retail banking, but it also targets payment processing and e‑commerce platforms in Brazil and Mexico.

🛡️ Mitigation

Defenders should deploy endpoint detection and response (EDR) tools with behavioral rules to flag process injection, enable web filtering to block known malicious domains, and enforce multi‑factor authentication (MFA) for banking websites. Regular user awareness training against spear‑phishing and strict application control to prevent untrusted executables from running are recommended.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.