JhoneRAT

First seen
2020-01-01 00:00:00
Malware type
rat
Profile updated
2026-07-07 13:21:11

Targeted industries: government-and-public-sector

Targeted regions: country_code:sa country_code:iq country_code:eg country_code:ly country_code:dz country_code:ma country_code:tn country_code:om country_code:ye country_code:sy country_code:ae country_code:kw country_code:bh country_code:lb

Context

Cisco Talos identified JhoneRAT in January 2020. The RAT is delivered through cloud services (Google Drive) and also submits stolen data to them (Google Drive, Twitter, ImgBB, GoogleForms). The actors using JhoneRAT target Saudi Arabia, Iraq, Egypt, Libya, Algeria, Morocco, Tunisia, Oman, Yemen, Syria, UAE, Kuwait, Bahrain and Lebanon.

Reports & references

  • cybereason.com — Molerats In The Cloud New Malware Arsenal Abuses Cloud Platforms In Middle East Espionage Campaign (report)
  • Cisco Talos — 2020 Year In Malware (report)
  • Palo Alto Unit 42 — Molerats Delivers Spark Backdoor (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Jhone Rat (report)
  • Cisco Talos — Jhonerat (report)

External references