Jupiter

Aliases: EarlyRAT

First seen
2019-06-15 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 15:07:57

Targeted industries: government-and-public-sector financial-services

Targeted regions: country_code:us country_code:ru country_code:cn

Context

Jupiter, also known as EarlyRAT, is a remote access tool primarily used for cyber espionage. It targets government and financial sectors, enabling attackers to remotely control compromised systems and exfiltrate sensitive information.

Detection coverage

  • 2 YARA rules

Detection rules

  • SIGNATURE_BASE_MAL_APT_NK_Trifaux_Easyrat_JUPITER (yara-rule)
  • MALPEDIA_Win_Jupiter_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Jupiter (report)
  • medium.com — Andariels Jupiter Malware And The Case Of The Curious C2 Dbfe29F57499 (report)
  • Kaspersky — 110119 (report)

External references