#Joanap

Malware/Tool

2018-05-29 • HIDDEN COBRA – Joanap Backdoor Trojan and Brambul Server Message Block Worm

Joanap is a remote-access backdoor used by North Korean HIDDEN COBRA actors. It commonly reaches systems as a file dropped by other HIDDEN COBRA malware after users visit compromised websites or open malicious email attachments. In the analyzed dropper chain, the dropper checks for the SCardPrv service and creates scardprv.dll, Wmmvsvc.dll, and an mssscardprv.ax file containing IP addresses and ports. Scardprv.dll provides the backdoor functionality, while Wmmvsvc.dll uses the listed network information for SMB worm activity. Government analysis linked Joanap infrastructure to 87 compromised network nodes used to preserve access and support exploitation of victim networks.

Tagged Reports

« Back