jason
- Malware type
- credential-stealer, exploit-kit
- Family
- Malware family
- Last IoC activity
- 2026-04-13 16:56:19
- Profile updated
- 2026-07-07 12:49:03
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications
Context
Jason is a graphic tool implemented to perform Microsoft exchange account brute-force in order to “harvest” the highest possible emails and accounts information. Distributed in a ZIP container the interface is quite intuitive: the Microsoft exchange address and its version shall be provided. Three brute-force methods could be selected: EWS (Exchange Web Service), OAB (Offline Address Book) or both (All). Username and password list can be selected and threads number should be provided in order to optimize the attack balance.
Reports & references
- secureworks.com — Cobalt Gypsy (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Jason (report)
- twitter.com — 1135503765287657472 (report)
- marcoramilli.com — Apt34 Jason Project (report)