logo

Increase in jRAT Campaigns

ID: 528c03fb-ea6a-5dd3-944f-0d25a3ffa974

STIX ID: report--528c03fb-ea6a-5dd3-944f-0d25a3ffa974

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-09-18

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ reports a surge in Java-based remote access Trojan (jRAT) infections delivered as malicious JAR attachments (e.g., "IRS UPDATES.jar", invoice/PO lures). The analysis describes a multi-layer packed sample that drops a VBS, checks for AV/firewalls, decrypts an embedded AES-encrypted jRAT (RSA-wrapped key), establishes C2 communication, persists via autostart registry entries, can download additional payloads, and can spy via the victim's camera; the report also provides filenames and a malicious URL observed during analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.