JAKU
ID: 3066dce9-4eaf-4d4b-9042-8b276cf60e73
STIX ID: report--3066dce9-4eaf-4d4b-9042-8b276cf60e73
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2016-05-04
Last Modified Date: 2016-05-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Forcepoint's JAKU analysis describes a sophisticated, large-scale botnet campaign that combined poisoned BitTorrent distribution and multi-stage malware (including fake PNG second stages and custom RC4/LZH routines) to infect roughly 19k unique victims while simultaneously running a small, targeted espionage operation against individuals linked to North Korea; the report provides deep technical breakdowns of binaries, stealth persistence (process injection, Active Setup), multi-protocol C2 mechanisms (HTTP, DNS, UDT/TCP), SQLite-based telemetry, victim geography/demographics, C2 infrastructure and numerous IoCs.
