JDownloader site hacked to replace installers with Python RAT malware
ID: 7048969e-5e46-574d-aa8e-f419af5d56a8
STIX ID: report--7048969e-5e46-574d-aa8e-f419af5d56a8
Feed Name: Bleeping Computer
Threat Score
The official JDownloader website was compromised between May 6–7, 2026 to serve trojanized Windows and Linux installers: Windows installers deployed a heavily obfuscated Python-based RAT that fetches and executes code from observed C2 domains, and the Linux installer installed SUID-root binaries, persistence scripts, and an obfuscated payload; affected users who executed the altered installers are advised to reinstall systems and reset credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
