JessieConTea

Malware type
rat, trojan
Family
Malware family
Profile updated
2026-07-07 14:54:18

Targeted industries: financial-services technology-and-telecommunications

Context

JessieConTea is a remote access trojan that uses HTTP(S) for communication. It supports around 30 commands that include operations on the victim’s filesystem, basic process management, file exfiltration (both plain and zipped), and the download and execution of additional tools from the attacker’s arsenal. The commands are indexed by 32-bit integers, starting with the value 0x60D49D97. The malware was delivered in-the-wild via trojanized applications like DeFi Wallet or Citrix Workspace. JessieConTea generates POST parameters with a specific parameter name, jsessid, from which the initial part of its name is derived. Also, it contains a specific RTTI symbol ".?AVCHttpConn@@", which inspired the second part of the name. It uses RC4 for C&C traffic encryption.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Jessiecontea_Auto (yara-rule)

Reports & references

  • cn.ahnlab.com — Asec%20Report Vol.102 Eng%20(4) (report)
  • Cisco Talos — Fake Korean Job Posting (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Jessiecontea (report)
  • asec.ahnlab.com — 57685 (report)
  • Kaspersky — 106195 (report)

External references