Jeno

Malware

⚠️ Overview

Jeno is a remote access trojan (RAT) first documented by researchers at Cisco Talos in June 2022, attributed to the financially motivated threat group TA421 (also tracked as UNC1945). It is primarily used for credential theft and reconnaissance, falling under the stealer and backdoor malware categories.

🔧 Technical Capabilities

Jeno propagates through weaponized Microsoft Office documents exploiting CVE-2021-40444 (MSHTML remote code execution) and CVE-2017-0199 (COM Object linking). Its command-and-control (C2) infrastructure relies on encrypted HTTPS traffic to hard-coded domains and uses a custom base64-like encoding for beaconing. Persistence is achieved through a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun and a scheduled task named "BackgroundCacheUpdate." Evasion techniques include AMSI patching via direct memory modification, process hollowing into legitimate Windows binaries like svchost.exe, and dynamic API resolution to avoid static detection. It also employs sandbox detection by checking for common analysis tools (e.g., wireshark.exe, procexp.exe) and hibernation file size anomalies.

📜 History & Notable Incidents

First observed in the wild during early 2022, Jeno was linked to a campaign targeting logistics firms in Southeast Asia in September 2022, where it exfiltrated shipping manifests. No high-profile victims have been publicly named, and no CVEs have been exclusively associated with the malware itself. Law enforcement actions have not been reported, though the group's infrastructure was partially disrupted by a sinkhole operation by the Shadowserver Foundation in November 2022.

🔍 Detection Indicators

Known SHA256 hashes include a3f7b9c1d2e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 (sample from VirusTotal). Behavioral signatures include the creation of the mutex JenoSessionMutex and the registry key HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerJeno. Network IOCs are specific C2 domains such as jenoserver[.]com and User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) JenoBot/1.0.

☠️ Risk & Impact

Jeno steals browser credentials, email account data, and FTP client configurations, leading to direct financial losses from account takeover. Affected sectors include logistics, retail, and small-to-medium enterprises, with incident response reports indicating an average data exfiltration volume of 500 MB per compromised host. No ransomware functionality has been observed, but the backdoor allows lateral movement for secondary payloads.

🛡️ Mitigation

Defenders should block execution of Office macros originating from external sources, deploy endpoint detection rules for process hollowing (MITRE ATT&CK T1055.012), and monitor for the JenoSessionMutex mutex. Patches for CVE-2021-40444 and CVE-2017-0199 should be applied immediately, and network teams can enforce TLS inspection to detect the custom beaconing pattern.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.