Verblecon

First seen
2021-06-01 00:00:00
Malware type
cryptominer, credential-stealer, loader
Family
Malware family
Profile updated
2026-07-07 14:32:28

Targeted industries: financial-services technology-and-telecommunications media-and-entertainment

Context

This malware seems to be used for attacks installing cryptocurrency miners on infected machines. Other indicators leads to the assumption that attackers may also use this malware for other purposes (e.g. stealing access tokens for Discord chat app). Symantec describes this malware as complex and powerful: The malware is loaded as a server-side polymorphic JAR file.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Jar.Verblecon (report)
  • Broadcom/Symantec — Verblecon Sophisticated Malware Cryptocurrency Mining Discord (report)

External references