JDownloader Downloader Hacked to Infect Users With New Python RAT
ID: d868f0a0-7686-505d-b9b8-83952cd3ceda
STIX ID: report--d868f0a0-7686-505d-b9b8-83952cd3ceda
Feed Name: cybersecurityNews.com
Threat Score
In early May 2026 attackers exploited an unpatched CMS vulnerability on jdownloader.org to swap legitimate download links with malicious unsigned installers that bundled the real installer plus an XOR- and PyArmor-protected Python remote access trojan, enabling persistent, encrypted C2 communications and arbitrary remote code execution for victims who downloaded the affected files between May 6–7.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
