Joanap Remote Access Trojan and Brambul Worm
Two new malware tools used by the HIDDEN COBRA advanced persistent threat (APT) group have been identified. Joanap, a remote access trojan (RAT), and Brambul, an information stealing worm, have been observed targeting finance, infrastructure and government organisations in Western Europe and the USA.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Two new malware tools used by the HIDDEN COBRA advanced persistent threat (APT) group have been identified. Joanap, a remote access trojan (RAT), and Brambul, an information stealing worm, have been observed targeting finance, infrastructure and government organisations in Western Europe and the USA.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication it is unclear how Joanap is distributed, although HIDDEN COBRA have previously used spam, phishing or watering-hole campaigns to deliver their other tools. Joanap is primarily used to enable peer-to-peer communication with HIDDEN COBRA botnets but is also able to exfiltrate data, initiate proxy communications with a command and control server and execute processes.
Brambul is delivered to a targeted device by a dropper or downloader, likely to be Joanap or some other HIDDEN COBRA related malware. Once installed it will launch a brute-force attack over SMB in order to gain access to other devices on the network. Newer Brambul variants will also collect system and user information and execute command-line scripts.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
Incoming traffic on ports 139 and 445 should be monitored and, if possible, these ports should be closed. Additionally, to prevent and detect an infection ensure that:
|
Last edited: 11 November 2020 12:34 pm