216.73.217.22

Downloader Malware Written in JPHP Interpreter

· Published 17/04/2025 16:34 · Modified 17/04/2025 19:39

Export JSON

Essential information

Published
17/04/2025 16:34
Modified
17/04/2025 19:39
Tags
2025-04-17 danabot jphp php strrat
Related entities
4 observables, 5 techniques (mitre), 2 malware

Description

A newly discovered malware utilizes , a interpreter running on Java Virtual Machine, to create a downloader. The malware is distributed in a ZIP file containing Java Runtime Environment and libraries, enabling execution without a separate Java environment. It communicates with a C2 server, disables Windows Defender's behavior monitoring, and uses Telegram for additional C2 connections. The malware can download and execute additional payloads, potentially including data breach-type malware like and . This case highlights how threat actors exploit lesser-known technologies like for malware distribution, emphasizing the importance of scrutinizing executable files and scripts from various sources.

External references