VORANT. Threat Intelligence Sign in Get the full feed

Adwind RAT C2s traced to AnMaXX hosting

medium threat

Cross-platform Java RAT Adwind (jRAT/JSocket), sold as malware-as-a-service, is spreading via spam and using bulletproof-style hosting from a provider dubbed AnMaXX.

Adwind, also known as jRAT or JSocket, is a Java-based remote access trojan capable of infecting Windows, macOS, Linux, and Android systems as long as a Java runtime is present. Active since 2012 and gaining traction over the past several years, the malware has been distributed as malware-as-a-service through the JSocket.org platform, offering subscribers AV evasion, VPN services, and technical support. Primary infection occurs through spam emails carrying ZIP archives with malicious .jar files or links to download URLs serving the payload, and Trend Micro previously reported enterprise and industrial targeting involving Adwind in early 2017.

The researcher identified dozens of Adwind botnet command-and-control servers hosted across 17 IP prefixes rented and operated by a hosting entity referred to as "AnMaXX," which does not announce its own AS but leases IP space from various providers across multiple countries (Switzerland, Norway, Russia, Romania, UK, Macedonia, France, Netherlands, Germany, Serbia, Czech Republic). Two of the listed WHOIS records share the same registrant email address, suggesting common control over portions of this infrastructure. The advisory recommends organizations monitor outbound traffic to these prefixes (excluding ports 80/443 to reduce false positives) as an indicator of Adwind infection within their networks.

Mentioned in this report

Malware AdWind

Source reporting: https://abuse.ch/blog/adwind-a-cross-plattform-rat

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free