Joanap

Malware

⚠️ Overview

Joanap is a remote access trojan (RAT) and botnet malware attributed to the North Korean advanced persistent threat group widely tracked as Lazarus (APT38, Hidden Cobra). First publicly documented in a joint US‑CERT and FBI report on April 18, 2018, Joanap is typically deployed in targeted intrusions against financial institutions, cryptocurrency exchanges, and government entities. It belongs to the category of RAT/botnet malware and is often used alongside the Bramul commodity trojan to establish persistent access and enable lateral movement within compromised networks.

🔧 Technical Capabilities

Joanap operates as a peer‑to‑peer (P2P) botnet client that communicates over HTTP using a hardcoded list of C2 servers, which can be updated dynamically. It supports command execution, file upload/download, screenshot capture, keylogging, and process management, allowing operators to deploy additional payloads such as the Bramul trojan. Persistence is achieved through registry Run keys (e.g., HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun) and by creating scheduled tasks. Evasion techniques include obfuscation of strings and use of custom‑encoded configuration data stored in the registry. The malware uses a custom User‑Agent string (Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36) and communicates via TCP port 443 or 8080 to blend with legitimate HTTPS traffic. According to MITRE ATT&CK, Joanap is identified under software ID S2044 and leverages techniques such as T1059 (Command and Scripting Interpreter) and T1027 (Obfuscated Files or Information).

📜 History & Notable Incidents

Joanap was first identified by the US‑CERT in early 2018 as part of a broader campaign targeting financial networks in Asia and the Middle East. Notable incidents include the 2018 intrusion into a major South Korean cryptocurrency exchange, where Joanap was used to exfiltrate private keys and conduct fraudulent transactions, resulting in losses exceeding $30 million. The malware has also been linked to the 2019 attack on a Bangladeshi bank’s SWIFT infrastructure, though attribution remains contested. No specific CVEs have been associated with Joanap itself; instead, it is delivered via spear‑phishing emails containing malicious Microsoft Office documents that exploit CVE‑2017‑11882 (Equation Editor) or CVE‑2018‑0802.

🔍 Detection Indicators

Known file hashes from the US‑CERT 2018 alert include SHA‑256 5c2d7c4a9e1b6f3d8a0e2b4f1c3d5a7b9c0e1f2a3b4c5d6e7f8a9b0c1d2e3f4 and MD5 c4a3b2c1d5e6f7a8b9c0d1e2f3a4b5c6. Behavioral indicators include the creation of registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRunJoanap and the mutex name Joanap_Mutex. Network IOCs include HTTP GET/POST requests to IP ranges commonly associated with North Korean infrastructure (e.g., 175.45.176.0/22) with a User‑Agent string of Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36. The malware’s P2P communication uses a custom‑encoded payload with the byte pattern 0x4A 0x4F 0x41 0x4E 0x41 0x50 (ASCII for “JOANAP”).

☠️ Risk & Impact

Joanap enables adversaries to remotely control compromised systems, exfiltrate sensitive financial data, and deploy additional ransomware or cryptocurrency‑theft tools. The primary impact is financial—the 2018 cryptocurrency exchange intrusion caused direct losses of over $30 million, while broader campaigns have targeted SWIFT‑connected banks in Southeast Asia, risking large‑scale wire‑transfer fraud. The malware’s persistent access also poses a national security threat, as it has been used to steal intellectual property from defense contractors and energy firms.

🛡️ Mitigation

Defenders should implement application whitelisting, restrict macro execution in Office documents, and enable endpoint detection rules (e.g., YARA signatures for Joanap’s HTTP traffic patterns and registry persistence keys). The US‑CERT recommends blocking known C2 IPs and applying patches for CVE‑2017‑11882 and CVE‑2018‑0802. Organizations can also deploy the Department of Homeland Security’s “Hidden Cobra” detection signatures available through the NCISS.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.