SysJoker is a cross-platform backdoor malware family targeting Windows, Linux, and macOS. First observed in late 2021 and publicly reported in early 2022, it is designed for espionage-oriented post-compromise activity, including host reconnaissance, persistence, command-and-control communication, and delivery or execution of additional payloads. Early variants were written in C++, and later Windows variants were rewritten in Rust, indicating continued development and operational investment.
Across platforms, SysJoker uses operating-system-specific implementations while preserving a common workflow. It installs itself under names and locations intended to resemble legitimate software or system components, delays execution with randomized sleep intervals to reduce detection, gathers host metadata, and contacts a dynamically resolved command-and-control endpoint. The malware has used cloud-hosted indirection to obtain current C2 information, including services such as Google Drive and later OneDrive, allowing operators to rotate infrastructure without changing the implant.
On Windows, SysJoker has been observed using a DLL-based first-stage dropper and PowerShell-assisted execution chains. It copies or extracts itself into systemwide data directories, masquerades as benign software components, and establishes persistence through the current-user Run key. It performs reconnaissance using native system utilities to collect information such as operating system details, network configuration, MAC address, disk identifiers, and username. Collected data is staged, encoded, and transmitted to the C2 server during initial registration. Subsequent tasking can include downloading and executing additional malware, and some variants support command execution with result upload. More recent Windows variants introduced greater complexity, including multi-stage chains, token-based C2 interactions, encrypted configuration retrieval, and archive extraction for follow-on payload deployment.
On Linux and macOS, SysJoker implements equivalent backdoor behavior with platform-native persistence. Linux variants have used reboot-triggered cron persistence, while macOS variants copy themselves into user or system library locations and create LaunchAgent entries to run at login. The macOS implant has been observed as a universal Mach-O binary supporting both Intel and Apple Silicon systems. The macOS and Linux variants likewise perform host profiling, retrieve dynamic C2 information, and support remote execution workflows.
SysJoker is notable for blending commodity tradecraft with cross-platform engineering. It relies on living-off-the-land utilities, masquerading, delayed execution, encoded configuration data, and cloud services for C2 indirection. Public reporting initially noted a lack of attribution, but later research linked newer SysJoker activity to targeted operations against Israeli entities and assessed use by a Hamas-affiliated threat actor. Reporting has also connected aspects of SysJoker tradecraft to earlier Gaza Cybergang or Molerats-associated activity, though such attribution remains an analytic assessment rather than a universally established fact.
Victimology associated with SysJoker includes educational institutions and other organizations in Israel, as well as a Linux server compromise that led to its discovery. The malware family remains significant because it demonstrates sustained multi-platform capability, iterative redevelopment, and use in politically motivated espionage campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Check Point Research is actively tracking the evolution of SysJoker, a previously publicly unattributed multi-platform backdoor... SysJoker, initially discovered ... by Intezer in 2021, is a multi-platform backdoor with multiple variants for Windows, Linux and Mac.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
On Linux , the files and directories are created under "/.Library/” while persistence is established by creating the following cron job: @reboot (/.Library/SystemServices/updateSystem).
Next, SysJoker will gather information about the machine using Living off the Land (LOtL) commands.
On Linux , the files and directories are created under "/.Library/” while persistence is established by creating the following cron job: @reboot (/.Library/SystemServices/updateSystem).
On macOS , the files are created on "/Library/” and persistence is achieved via LaunchAgent under the path: /Library/LaunchAgents/com.apple.update.plist.
On Linux , the files and directories are created under "/.Library/” while persistence is established by creating the following cron job: @reboot (/.Library/SystemServices/updateSystem).
“Download a DLL… save it to… MsoftInit.dll… Load the MsoftInit.dll and call the init exported function… download… MsoftNotify.dll… loads… resolves the function st… parameters r and k”
On macOS , the files are created on "/Library/” and persistence is achieved via LaunchAgent under the path: /Library/LaunchAgents/com.apple.update.plist.
The malware then sleeps for up to two minutes before creating a new directory and copies itself as an Intel Graphics Common User Interface Service ("igfxCUIService.exe”).
“Download a DLL… save it to… MsoftInit.dll… Load the MsoftInit.dll and call the init exported function… download… MsoftNotify.dll… loads… resolves the function st… parameters r and k”
These text files are deleted immediately, stored in a JSON object and then encoded and written to a file named "microsoft_Windows.dll”.
After gathering system and network data, the malware will create persistence... The system information collected in the first stages of the infection is sent as the first handshake to the C2.
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" getmac | Out-File -Encoding 'Default' 'C:\ProgramData\SystemData\temps1.txt' ; wmic path win32_physicalmedia get SerialNumber | Out-File -Encoding 'Default' 'C:\ProgramData\SystemData\temps2.txt'
wmic nicconfig where 'IPEnabled = True' get ipaddress > "C:\ProgramData\SystemData\tempi1.txt"
As for communications against C&C, it has been seen to use different domains drive.google.com or github to make it more difficult to detect traffic and perform rule creation.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware sample used to validate the analysis pipeline; the content highlights C2 API endpoint extraction and cross-tool verification during analysis. It is described as a known Mach-O sample of the SysJoker malware.
A named malware family referenced as having Rust variants; the content does not describe functionality beyond being an example of Rust-written malware.
SysJoker is a backdoor malware previously used by Hamas-affiliated hackers to target Israeli educational institutions, providing persistent access to compromised systems.
“Unlike other Hamas-associated threats, such as SysJoker, this cluster’s activity has persisted throughout the war in Gaza.”
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.