logo

JDownloader site hacked to replace installers with Python RAT malware

ID: 7048969e-5e46-574d-aa8e-f419af5d56a8

STIX ID: report--7048969e-5e46-574d-aa8e-f419af5d56a8

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-05-09

Date Updated: 2026-05-11

Author: Lawrence Abrams

...
...

The official JDownloader website was compromised between May 6–7, 2026 to serve trojanized Windows and Linux installers: Windows installers deployed a heavily obfuscated Python-based RAT that fetches and executes code from observed C2 domains, and the Linux installer installed SUID-root binaries, persistence scripts, and an obfuscated payload; affected users who executed the altered installers are advised to reinstall systems and reset credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.