Malware

jRAT

S0283 · Linux, Windows, macOS, Android

jRAT is a cross-platform, Java-based backdoor originally available for purchase in 2012. Variants of jRAT have been distributed via a software-as-a-service platform, similar to an online subscription model.

ATT&CK S0283 Malware family

Live Indicators

Indicators are defanged for safe handling. Newest first.
Aliases
jRAT, JSocket, AlienSpy, Frutas, Sockrat, Unrecom, jFrutas, Adwind, jBiFrost, Trojan.Maljava
External lookups - second-class, for what we don’t hold ourselves