YamaBot
Aliases: Kaos
- Malware type
- botnet
- Family
- Malware family
- Profile updated
- 2026-07-07 14:59:04
Targeted regions: country_code:jp
Context
YamaBot is a botnet primarily targeting Japanese systems, associated with cybercrime activities. Its functions include establishing remote control and potentially launching further attacks such as DDoS.
Detection coverage
- 2 YARA rules
Detection rules
- SEKOIA_Bot_Win_Yamabot (yara-rule)
- SIGNATURE_BASE_MAL_APT_NK_Andariel_Kaosrat_Yamabot (yara-rule)
Reports & references
- media.defense.gov — Csa Ransomware Attacks On Ci Fund Dprk Activities (report)
- Cisco Talos — Lazarus Three Rats (report)
- youtube.com — Watch (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Yamabot (report)
- blogs.jpcert.or.jp — Yamabot (report)
- Cisco Talos — Lazarus Three Rats (report)