Adwind Remote Access Trojan
Adwind remote access trojan (RAT), also known as jRAT, JSocket and AlienSpy, is being distributed via spam emails. The spam emails were observed to have numerous attachment titles.These include 'DHL Delivery Notice', 'Proforma Invoice', 'Request for Information', 'Transfer Import' and 'Swift Copy' among others. The spam email contains a malicious JAR file attachment.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Adwind remote access trojan (RAT), also known as jRAT, JSocket and AlienSpy, is being distributed via spam emails. The spam emails were observed to have numerous attachment titles.These include 'DHL Delivery Notice', 'Proforma Invoice', 'Request for Information', 'Transfer Import' and 'Swift Copy' among others. The spam email contains a malicious JAR file attachment.
Affected platforms
The following platforms are known to be affected:
Threat details
These include 'DHL Delivery Notice', 'Proforma Invoice', 'Request for Information', 'Transfer Import' and 'Swift Copy' among others. The spam email contains a malicious JAR file attachment.
Adwind RAT has the following functions:
- collect keystrokes
- steal cached passwords and grab data from web forms
- take screenshots
- take pictures and record video from a webcam
- record sound from a microphone
- transfer files
- collect general system and user information
- steal keys for cryptocurrency wallets
- manage SMS (for Android)
- steal Virtual Private Network (VPN) certificates
Threat updates
Remediation advice
To prevent and detect an infection, ensure:
Remediation steps
| Type | Step |
|---|---|
|
CVE Vulnerabilities
Last edited: 11 January 2022 11:33 am