Skip to content

Latest commit

 

History

History
64 lines (38 loc) · 2.82 KB

malware.md

File metadata and controls

64 lines (38 loc) · 2.82 KB

Malware

Java.Chesire.A

Links

Description: Chesire is a self-replicating piece of Java malware targeting Java 8 and above written by B0t of VX-Underground.

CurseForge Fractureiser

Links

Description: Malicious actors creates a self-replicating Java malware that explicitly targeted the modding/plugin communities. It spreads to all JAR files on the local system, and stolen credentials of mod authors are used by the bad actor to upload backdoored versions of their mods to hosting sites like CurseForge.

Squished Worm

Links

Description: Squished Worm is Java malware that targets Bukkit plugins, and supports persistence injection into adjacent server files, and remote SSH/FTP access.

StrRat / Strigoi

Links

Description: StrRat is a dynamic, plugin-extensible Java RAT. After moving on from just credential stealing, it later gained ransomware like-abilities.

jRat

Links

Description: Common back in its active years (ending around 2014) it was the primary go-to Java malware for quite some time.

Cobalt Stike

Links

Description: A tool for post-exploitation pentesting written in Java, commonly used by bad actors for their own real C2 servers.

(Back to README)