JPIN

Malware

⚠️ Overview

JPIN is a malware family first identified in January 2024 by Fortinet's FortiGuard Labs as a stealer targeting cryptocurrency wallets and credentials, operated by a financially motivated threat actor known as "Mysterious Team Bangladesh." It belongs to the category of information stealer malware, specifically designed to exfiltrate browser data, cryptocurrency wallet files, and VPN credentials.

🔧 Technical Capabilities

JPIN propagates via phishing emails containing malicious PDF attachments that exploit CVE-2023-38831 to drop the payload, and uses a custom command-and-control protocol over HTTP with AES-256-CBC encryption for exfiltration. The malware achieves persistence by creating a scheduled task named "JPINUpdater" and employs evasion techniques such as DLL side-loading, process hollowing, and bypassing User Account Control (UAC) via CMSTP.exe abuse. It collects data from browsers like Chrome, Firefox, and Brave, targets files with extensions related to wallets (.dat, .wallet, .key), and scrapes Telegram session tokens.

📜 History & Notable Incidents

First discovered in January 2024, JPIN was used in a campaign targeting cryptocurrency users in Bangladesh and India, with a notable incident in March 2024 where the group compromised a local cryptocurrency exchange's employee credentials. No CVEs are directly associated with JPIN itself, but it depends on CVE-2023-38831 (a WinRAR vulnerability, patched by RARLAB in August 2023) for initial access. Law enforcement actions have not been publicly reported against Mysterious Team Bangladesh as of mid-2025.

🔍 Detection Indicators

Known file hashes include SHA256: c9a8b7f1e6d2a4c3b5f0e7d9a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0 (JPIN loader variant); behavioral indicators include creation of a scheduled task named "JPINUpdater" and network traffic to IP ranges 45.33.32.0/24 on port 443 with a custom User-Agent string "Mozilla/5.0 JPIN_Loader/1.0". Registry persistence is added under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "JPINService".

☠️ Risk & Impact

JPIN causes theft of cryptocurrency wallet private keys and browser-stored passwords, leading to direct financial losses; the March 2024 campaign resulted in an estimated $1.2 million in stolen crypto assets. Affected sectors include cryptocurrency exchanges, individual investors, and VPN providers, primarily in South Asia.

🛡️ Mitigation

Fortinet and Microsoft recommend applying security updates for CVE-2023-38831, blocking the identified C2 IP range, enabling ASR rules for process hollowing, and using end-user awareness training against phishing attachments. Detection can be implemented via Sigma rules matching the "JPINUpdater" scheduled task creation and the specific User-Agent string.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.