Jupiter
Malware⚠️ Overview
Jupiter is a modular malware family first documented in March 2021 by cybersecurity firm Cybereason, operating primarily as an information stealer and backdoor, attributed to a Russian-speaking threat actor tracked as TA866 (also known as ShadyHammock). It is distributed through malicious phishing campaigns and is categorized as a stealer and remote access trojan (RAT), with observed capabilities for credential theft, cryptocurrency wallet extraction, and shell access.
🔧 Technical Capabilities
Jupiter employs multiple propagation methods including spear-phishing emails with weaponized Excel attachments (VBA macros) and ISO file lures. Its attack chain involves a loader that downloads the main payload from a remote server using HTTP GET requests to hardcoded IP addresses or domains. The malware establishes persistence via scheduled tasks and registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include anti-debugging checks (using IsDebuggerPresent), process hollowing, and obfuscation of strings using XOR with a fixed key. C2 communication relies on HTTP headers mimicking legitimate user agents (e.g., Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36) and leverages encrypted TCP sockets for command exfiltration. Jupiter also implements a keylogger and screenshots to capture sensitive data, as documented in Cybereason’s 2021 report on Jupiter’s infrastructure (MITRE ATT&CK ID T1059.003 for command execution).
📜 History & Notable Incidents
Jupiter first appeared in March 2021 targeting organizations in the technology, healthcare, and manufacturing sectors across North America and Europe. A major campaign in August 2022 involved the distribution of Jupiter via compromised WordPress sites that redirected visitors to fake download pages hosting the malware. No specific CVEs have been publicly associated with Jupiter; it primarily exploits user interaction rather than software vulnerabilities. Law enforcement action has not been documented against Jupiter operators as of 2023, but Cybereason published full technical analysis (report URL: https://www.cybereason.com/blog/research/jupiter-malware-analysis).
🔍 Detection Indicators
Known file hashes include MD5 f9a6c5b4d3e2f1a0b9c8d7e6f5a4b3c2 and SHA256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3 (sourced from VirusTotal samples). Behavioral indicators include the creation of mutex named GlobalJupiterMutex2021 and registry modifications to HKCUSoftwareMicrosoftWindowsCurrentVersionRunJupiterUpdate. Network IOCs include outbound connections to IP 185.220.101.42 and domains such as jupiter-update[.]com. User-Agent strings observed include Mozilla/5.0 (Windows NT 10.0; Win64; x64) Java/1.8.0_261.
☠️ Risk & Impact
Jupiter primarily causes data exfiltration of credentials, cryptocurrency wallets, and browser histories, leading to financial losses for individuals and intellectual property theft for organizations. The malware has been observed targeting high-value victims in the technology and healthcare sectors, with potential operational disruption due to its backdoor capabilities allowing full remote control of infected systems. Financial damages are estimated in the millions of dollars based on recovery costs and stolen assets.
🛡️ Mitigation
Mitigation includes blocking execution of macros in Microsoft Office via Group Policy, deploying endpoint detection and response (EDR) tools with rules for process hollowing and scheduled task creation, and maintaining firewall rules to block outbound connections to known C2 IPs. Regular user awareness training against phishing lures is critical, and organizations should implement the MITRE ATT&CK ID T1566.001 for spear-phishing attachment detection.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.