DADJOKE

First seen
2019-01-01 00:00:00
Malware type
downloader, loader
Family
Malware family
Profile updated
2026-07-07 14:56:10

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:vn

Context

DADJOKE was discovered as being distributed via email, targeting a South-East Asian Ministry of Defense. It is delivered as an embedded EXE file in a Word document using remote templates and a unique macro using multiple GET requests. The payload is deployed using load-order hijacking with a benign Windows Defender executable. Stage 1 has only beacon+download functionality, made to look like a PNG file. Additional analysis by Kaspersky found 8 campaigns over 2019 and no activity prior to January 2019, DADJOKE is attributed with medium confidence to APT40.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Dadjoke_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Dadjoke (report)
  • youtube.com — Watch (report)
  • wemp.app — 80Ab2B2D 4E0E 4960 94B7 4D452A06Fd38 (report)
  • twitter.com — 1110941178231484417 (report)
  • prezi.com — Jgyazyy5Dtokdrtwsji5 (report)
  • twitter.com — 1154764787823316993 (report)
  • medium.com — Apt 40 In Malaysia 61Ed9C9642E9 (report)

External references