VORANT. Threat Intelligence Sign in Get the full feed

JPCERT recaps JSAC2026 malware research talks

low threat technologytelecommunicationsgovernment-national

JSAC2026 workshops and lightning talks covered email forensics, Guloader/Gremlin reverse engineering, .NET AOT malware analysis, HoldingHandsRAT phishing in Japan, and GitHub-based malvertising delivering HijackLoader and AMOS Stealer.

This JPCERT/CC report summarizes the workshop, lightning talk, and panel sessions from the JSAC2026 conference. Technical workshops covered email header/authentication analysis (SPF/DKIM/DMARC) using the EML Analyzer tool, reverse engineering of the Guloader dropper and Gremlin infostealer with a focus on anti-analysis and VEH-based control-flow obfuscation, and techniques for analyzing .NET Native AOT-compiled malware using Ghidra and IDA Pro signature matching.

Lightning talks detailed real-world threats: a HoldingHandsRAT phishing campaign against Japanese organizations using password-protected executables and stolen digital signatures, SPF/DMARC weaknesses in shared hosting infrastructure enabling spoofing, browser-extension tooling (TOAMI/IKESU/CHOKA) for phishing-site takedown workflows, and a malvertising campaign abusing forked GitHub repositories to distribute HijackLoader (Windows) and AMOS Stealer (macOS) to developers searching for tools like GitHub Desktop. Additional talks touched on an Initial Access Broker-linked activity dubbed Houken (largely TLP:RED) and abuse of Japanese mobile lines for SMS verification bypass in investment/romance scams.

Overall this is a conference recap rather than an active-threat advisory; most content is informational, though it references genuinely observed campaigns (HoldingHandsRAT, GitHub malvertising) that defenders in Japan and the developer community should be aware of. No specific indicators of compromise were disclosed in the article itself.

Mentioned in this report

Threat actors Houken
Malware AMOS StealerCoGUIGremlinGuLoaderHijackLoaderHoldingHandsRAT

Source reporting: https://blogs.jpcert.or.jp/en/2026/03/jsac2026-ws-lt-pd.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free