A form of trojan malware that has been used by cybercriminals to steal login credentials and other information from victims for over five years has been updated with the ability to hide itself using legitimate Java to cover up its malicious behavior.
The Adwind remote access trojan (RAT) – also known as AlienSpy and jRAT – first appeared in 2013 and is available as a service to criminals who want to use their credentials, keylogging, audio recording and other malware capabilities against victims.
The malware can target users of many major operating systems and typically infects victims through phishing emails,corrupted software , or malicious websites.

Now a new variant of the malware has emerged, appearing to specifically target Windows and common Windows applications, including Internet Explorer and Outlook, along with Chromium-based browsers such as Brave – which was only released this year.
More detailed from the researchers at Menlo Security, the latest incarnation of Adwind is delivered via a JAR file (Java Archive), with its malicious intent being hidden behind multiple layers of packaging and encryption, so that signature‑based detection becomes ineffective.
Once the malware unpacks a list of command and control server addresses, Adwind is activated and is able to receive commands and send stolen data to the hosts , including banking credentials, enterprise application logins , and passwords stored in a browser .
This latest version of Adwind also hides its behavior, while at the same time acting like any other Java command, allowing the activity to appear without being detected.
The authors do this by hiding malicious JAR files among many legitimate JAR applications, using encryption to make the original JAR file difficult to detect, and loading additional JAR files from a remote server. All of this makes it difficult to detect abnormal activity.
“It's like being inside a crowd of millions of people and trying to pick out the one person wearing a green shirt without being able to look under people's jackets. There's nothing suspicious about his existence, his appearance, or even his initial behavior, it seems normal. ” said Krishnan Subramanian, security researcher at Menlo Labs.
However, Adwind lets its mask slip in one way: when sending stolen credentials to a remote server, it uses non- Java -related commands — although since the malware sends information to attackers, it has. “From a detection perspective, visibility into online and electronic traffic is essential. These jRAT filenames seem to have a pattern using common financial terms like ‘Remittance’, ‘Payment’, ‘Advice’. Check the filename of a Java Application before invoking it,” Subramanian said.
