logo

JAKU

ID: 3066dce9-4eaf-4d4b-9042-8b276cf60e73

STIX ID: report--3066dce9-4eaf-4d4b-9042-8b276cf60e73

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2016-05-04

Last Modified Date: 2016-05-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Forcepoint's JAKU analysis describes a sophisticated, large-scale botnet campaign that combined poisoned BitTorrent distribution and multi-stage malware (including fake PNG second stages and custom RC4/LZH routines) to infect roughly 19k unique victims while simultaneously running a small, targeted espionage operation against individuals linked to North Korea; the report provides deep technical breakdowns of binaries, stealth persistence (process injection, Active Setup), multi-protocol C2 mechanisms (HTTP, DNS, UDT/TCP), SQLite-based telemetry, victim geography/demographics, C2 infrastructure and numerous IoCs.