#Jupiter

Malware/Tool

2023-05-16 • Andariel’s “Jupiter” malware and the case of the curious C2

Jupiter is a PureBasic Windows loader attributed to Andariel and observed in a small number of targeted attacks since 2020. It collects local IP addresses, computer and user names, Windows version, and system bitness, then communicates with command-and-control servers through manually implemented HTTP. POST fields use rotating XOR and Base64 encoding. Operators can issue shell commands, receive console output, or deliver files to chosen paths. Downloaded executables may be padded with roughly 40 MB of random data and timestomped with Explorer.exe metadata to impede security scanning and analysis.

Tagged Reports

« Back