YamaBot

Aliases: Kaos

Malware type
botnet
Family
Malware family
Profile updated
2026-07-07 14:59:04

Targeted regions: country_code:jp

Context

YamaBot is a botnet primarily targeting Japanese systems, associated with cybercrime activities. Its functions include establishing remote control and potentially launching further attacks such as DDoS.

Detection coverage

  • 2 YARA rules

Detection rules

  • SEKOIA_Bot_Win_Yamabot (yara-rule)
  • SIGNATURE_BASE_MAL_APT_NK_Andariel_Kaosrat_Yamabot (yara-rule)

Reports & references

  • media.defense.gov — Csa Ransomware Attacks On Ci Fund Dprk Activities (report)
  • Cisco Talos — Lazarus Three Rats (report)
  • youtube.com — Watch (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Yamabot (report)
  • blogs.jpcert.or.jp — Yamabot (report)
  • Cisco Talos — Lazarus Three Rats (report)

External references