JPIN is a Windows malware family associated with the China-linked espionage group PLATINUM. It has been used in long-term cyber-espionage operations targeting government and related organizations in South and Southeast Asia. JPIN functions as a modular backdoor and surveillance implant that supports host reconnaissance, credential collection, and stealthy execution on compromised systems.
Observed capabilities include enumerating running processes and services, collecting the current username, gathering local network configuration details such as DNS, IP, and proxy information, and enumerating Windows Registry keys. JPIN also contains a custom keylogger and can lower host security settings through Registry modification, indicating both credential-access and defense-evasion functionality. In addition, it has been observed injecting content into lsass.exe to load a module, demonstrating process-injection behavior for stealth and execution within a trusted process.
JPIN includes anti-analysis and self-protection logic. Its installer or uninstaller component checks for the presence of security-related processes and deletes itself if such processes are detected. It also self-deletes when executed on unsupported legacy Windows versions earlier than Windows XP. Reporting on PLATINUM-linked tooling indicates JPIN is used to obtain system information, load a keylogger, download files and updates, and extract potentially sensitive files from victim environments.
The malware is best characterized as a backdoor used for post-compromise espionage, with integrated reconnaissance, keylogging, defense evasion, and module-loading capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Sandworm Team modified in-registry internet settings to lower internet security... Ember Bear disables Windows Defender via registry key changes... JPIN can lower security settings by changing Registry keys... POWERSTATS can disable Microsoft Office Protected View by changing Registry keys.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
JPIN uses a encrypted and compressed payload that is disguised as a bitmap within the resource section of the installer. Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. TEARDROP created and read from a file with a fake JPG header.
Sandworm Team modified in-registry internet settings to lower internet security... Ember Bear disables Windows Defender via registry key changes... JPIN can lower security settings by changing Registry keys... POWERSTATS can disable Microsoft Office Protected View by changing Registry keys.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware capable of injecting content into lsass.exe to load a module.
Backdoor that can obtain the victim username.
Obtains network information including DNS, IP, and proxy settings.
Obtains the victim username.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.