The polymorphic RAT maintains five different names to avoid detection
Security researchers at Kaspersky have discovered interesting aspects of the Adwind RAT, many of its strains, as well as information regarding its mode of operation.
The RAT is a type of malicious software that infects users' computers and covertly steals their data, giving attackers the ability to remotely access the infected systems, even taking full control of them.
There are many types of RATs in the underground markets of the internet, and one of the biggest and most well-known is the Adwind RAT, which the Kaspersky team analyzed at this year's Security Analyst Summit, which took place in Tenerife, Spain.
The software first appeared in January 2012 under the name Frutas RAT. Its interface was in Spanish and was available on the market of only a few countries. In 2013 the software's creator re‑launched the RAT under the name Adwind RAT, adding an English user interface as well as support for Android devices, beyond support for Windows, Mac, and Linux.
As Adwind became increasingly successful, attracting the attention of more and more law enforcement agencies, its creator rebranded it again in February 2014 (Unrecom RAT) and subsequently in October 2014 (AlienSpy), before the software received its current name in June 2015 (JSocket RAT).
Very few malware families have managed to survive more than a few weeks, let alone for four years. The success of Adwind can be attributed to a series of factors.
Initially, its success can be attributed to the fact that it is written in Java, a fact that allows it to run on four different operating systems (Windows, Mac, Linux, Android).
Furthermore, the creator of Adwind never stood idle, and as time passed, he continued to add more and more features to his RAT arsenal. In its current form, Adwind is one of the most dangerous espionage tools, providing intruders with capabilities:
- Keylogging and keystroke interception
- Recording and interception of temporarily stored passwords
- Taking screenshots
- Capturing photos and recording video via webcam
- Audio recording via microphone
- File transfer
- Theft of VPN network certificates
These various features made the RAT successful and in the end, it was no surprise that the creator of the malware decided to shift from a pay‑per‑instance commercial model to a hosted, subscription‑based service, which allowed him to charge per month for access to his tool. Prices rose from $ 30 (€ 27) to $ 200 (€ 180), based on the capabilities used.
With rough calculations, Kaspersky estimates that the author of Adwind has revenues of $200,000 (€180,000) annually, having provided the RAT to approximately 1,800 cybercriminals, who then used it for attacks against a total of 443,000 victims.

