#Joanap
Malware/Tool
2015-10-26 • Duuzer back door Trojan targets South Korea to take over computers
Joanap is a remote-access backdoor used by North Korean HIDDEN COBRA actors. It commonly reaches systems as a file dropped by other HIDDEN COBRA malware after users visit compromised websites or open malicious email attachments. In the analyzed dropper chain, the dropper checks for the SCardPrv service and creates scardprv.dll, Wmmvsvc.dll, and an mssscardprv.ax file containing IP addresses and ports. Scardprv.dll provides the backdoor functionality, while Wmmvsvc.dll uses the listed network information for SMB worm activity. Government analysis linked Joanap infrastructure to 87 compromised network nodes used to preserve access and support exploitation of victim networks.
-
5
Tagged Reports
-
5
Unique Authors
-
1,013
Active Days