Joanap
- First seen
- 2009-01-01 00:00:00
- Malware type
- botnet, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 12:46:42
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:kr
Context
Joanap is a remote access tool (RAT) commonly associated with North Korean threat actors such as the Lazarus Group. It is part of an extensive botnet operation aimed at conducting espionage and infrastructure attacks.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Joanap_Auto (yara-rule)
Reports & references
- Broadcom/Symantec — Viewdocument (report)
- Broadcom/Symantec — Attackers Target Dozens Global Banks New Malware (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
- us-cert.gov — Ta18 149A (report)
- acalvio.com — Lateral Movement Technique Employed By Hidden Cobra (report)
- secureworks.com — Nickel Academy (report)
- us-cert.gov — Ar18 149A (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Joanap (report)
- app.box.com — Xyyord0B806E6Or2Nh92Coxw2Areyyx4 (report)