Joanap

First seen
2009-01-01 00:00:00
Malware type
botnet, rat
Family
Malware family
Profile updated
2026-07-07 12:46:42

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:kr

Context

Joanap is a remote access tool (RAT) commonly associated with North Korean threat actors such as the Lazarus Group. It is part of an extensive botnet operation aimed at conducting espionage and infrastructure attacks.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Joanap_Auto (yara-rule)

Reports & references

  • Broadcom/Symantec — Viewdocument (report)
  • Broadcom/Symantec — Attackers Target Dozens Global Banks New Malware (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
  • us-cert.gov — Ta18 149A (report)
  • acalvio.com — Lateral Movement Technique Employed By Hidden Cobra (report)
  • secureworks.com — Nickel Academy (report)
  • us-cert.gov — Ar18 149A (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Joanap (report)
  • app.box.com — Xyyord0B806E6Or2Nh92Coxw2Areyyx4 (report)

External references