US-CERT issued an alert on two malware associated with North Korea-linked APT Hidden Cobra

The Department of Homeland Security (DHS) and the FBI issued a joint Technical alert on two strain on malware, the Joanap backdoor Trojan and Brambul Server Message Block worm, associated with the HIDDEN COBRA North Korea-linked APT group.

Source: cyberdefensemagazine

The US-CERT alert reads:

“Working with U.S. government partners, DHS and FBI identified Internet Protocol (IP) addresses and other indicators of compromise (IOCs) associated with two families of malware used by the North Korean government:

  • a remote access tool (RAT), commonly known as Joanap; and
  • a Server Message Block (SMB) worm, commonly known as Brambul.” 

“The U.S. Government refers to malicious cyber activity by the North Korean government as HIDDENCOBRA.”

The government experts have identified a range of IP addresses and other indicators of compromise (IOCs) associated with the two families of malware.

The first threat tracked as “Joanap” is a two-stage RAT that uses peer-to-peer communications to manage botnets and perform malicious activities such as data exfiltration, installation of further payloads and establish proxy communications on compromised Windows systems.

Joanapis a two-stage malware used to establish peer-to-peer communications and to manage botnets designed to enable other operations. Joanapmalware provides HIDDEN COBRA actors with the ability to exfiltrate data, drop and run secondary payloads, and initialize proxy communications on a compromised Windows device.” states the alert.

The second malware analyzed by the government researchers is a Windows 32-bit  Server Message Block (SMB) worm called “Brambul”.

Brambul is used as a service dynamic link library file or a portable executable file often dropped and installed onto target networks by dropper malware. More…

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

Blog at

Up ↑

%d bloggers like this: