DADJOKE
- First seen
- 2019-01-01 00:00:00
- Malware type
- downloader, loader
- Family
- Malware family
- Profile updated
- 2026-07-07 14:56:10
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:vn
Context
DADJOKE was discovered as being distributed via email, targeting a South-East Asian Ministry of Defense. It is delivered as an embedded EXE file in a Word document using remote templates and a unique macro using multiple GET requests. The payload is deployed using load-order hijacking with a benign Windows Defender executable. Stage 1 has only beacon+download functionality, made to look like a PNG file. Additional analysis by Kaspersky found 8 campaigns over 2019 and no activity prior to January 2019, DADJOKE is attributed with medium confidence to APT40.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Dadjoke_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Dadjoke (report)
- youtube.com — Watch (report)
- wemp.app — 80Ab2B2D 4E0E 4960 94B7 4D452A06Fd38 (report)
- twitter.com — 1110941178231484417 (report)
- prezi.com — Jgyazyy5Dtokdrtwsji5 (report)
- twitter.com — 1154764787823316993 (report)
- medium.com — Apt 40 In Malaysia 61Ed9C9642E9 (report)