jason

Malware type
credential-stealer, exploit-kit
Family
Malware family
Last IoC activity
2026-04-13 16:56:19
Profile updated
2026-07-07 12:49:03

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications

Context

Jason is a graphic tool implemented to perform Microsoft exchange account brute-force in order to “harvest” the highest possible emails and accounts information. Distributed in a ZIP container the interface is quite intuitive: the Microsoft exchange address and its version shall be provided. Three brute-force methods could be selected: EWS (Exchange Web Service), OAB (Offline Address Book) or both (All). Username and password list can be selected and threads number should be provided in order to optimize the attack balance.

Reports & references

  • secureworks.com — Cobalt Gypsy (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Jason (report)
  • twitter.com — 1135503765287657472 (report)
  • marcoramilli.com — Apt34 Jason Project (report)

External references