jRAT

S0283

Malware.View on attack.mitre.org

About this malware

jRAT is a cross-platform, Java-based backdoor originally available for purchase in 2012. Variants of jRAT have been distributed via a software-as-a-service platform, similar to an online subscription model.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1007
System Service Discovery

jRAT can list local services.

T1016
System Network Configuration Discovery

jRAT can gather victim internal and external IPs.

T1021.001
Remote Desktop Protocol

jRAT can support RDP control.

T1027
Obfuscated Files or Information

jRAT’s Java payload is encrypted with AES. Additionally, backdoor files are encrypted using DES as a stream cipher. Later variants of jRAT also incorporated AV evasion methods such as Java bytecode obfuscation via the commercial Allatori obfuscation tool.

T1027.002
Software Packing

jRAT payloads have been packed.

T1029
Scheduled Transfer

jRAT can be configured to reconnect at certain intervals.

T1037.005
Startup Items

jRAT can list and manage startup entries.

T1047
Windows Management Instrumentation

jRAT uses WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details.

T1049
System Network Connections Discovery

jRAT can list network connections.

T1056.001
Keylogging

jRAT has the capability to log keystrokes from the victim’s machine, both offline and online.

T1057
Process Discovery

jRAT can query and kill system processes.

T1059.003
Windows Command Shell

jRAT has command line access.

T1059.005
Visual Basic

jRAT has been distributed as HTA files with VBScript.

T1059.007
JavaScript

jRAT has been distributed as HTA files with JScript.

T1070.004
File Deletion

jRAT has a function to delete files from the victim’s machine.

View all 28 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Kaspersky Adwind Feb 2016 Open source
    Kamluk, V. & Gostev, A. (2016, February). Adwind - A Cross-Platform RAT. Retrieved April 23, 2019.
  2. jRAT Symantec Aug 2018 Open source
    Sharma, R. (2018, August 15). Revamped jRAT Uses New Anti-Parsing Techniques. Retrieved September 21, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.