Jokra, also detected as Trojan.Jokra, is destructive wiping malware used in the March 2013 attacks against South Korean banks, broadcasters, and other organizations. Its primary function is to render systems unusable by overwriting the master boot record and then overwriting disk contents regardless of file format. It also attempts to repeat the wiping process on attached or mapped drives, increasing impact across compromised environments.
Jokra has been associated with the 2013 South Korean destructive campaign often discussed in connection with DarkSeoul activity and has been linked by multiple researchers to broader North Korean threat activity, including clusters later associated with Lazarus or Stonefly/Andariel, although attribution has historically remained contested. The campaign targeted financial institutions, media organizations, and other critical businesses, causing widespread operational disruption.
A notable feature of Jokra is a cross-platform destructive component embedded in its Windows dropper. This module parses saved remote administration connection data from mRemote on infected Windows hosts, identifies SSH connections with root privileges, and uses those credentials to upload and execute a shell-based wiper on remote Unix-like systems. The Linux-oriented component is designed to wipe remote Linux machines and includes commands intended to affect additional Unix platforms such as SunOS, AIX, and HP-UX. This behavior demonstrates that Jokra’s operators sought to extend destructive effects beyond the initially infected Windows endpoint into remotely administered infrastructure.
Observed infection vectors for the 2013 campaign included e-mail-based delivery and abuse of a compromised patch-management auto-update mechanism. Jokra has also been observed alongside Backdoor.Prioxer.B and samples packed with a distinctive Jokra packer, suggesting use within a broader intrusion set rather than as a standalone commodity threat. Available reporting indicates the operation was focused on destruction rather than espionage or data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Wiping malware called Jokra (Trojan.Jokra) was used in this attack.
...linked to the Jokra (Tojan.Jokra) disk-wiping attacks against a number of South Korean banks and broadcasters.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Researchers discovered that attackers used data-wiping malware to cripple critical businesses throughout South Korea... infections that erased pertinent company files.
The attack defaced the website of a Korean ISP and also crippled servers belonging to a number of organizations.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Disk-wiping malware used in destructive attacks (wiper) against South Korean banks and broadcasters (as referenced).
Destructive wiping malware used in attacks against South Korean banks and broadcasting organizations, wiping hard drives and crippling systems.
A destructive malware used in the March 2013 attacks. It overwrites the MBR and hard drive contents regardless of file type, then attempts to overwrite mapped network drives as well. It was delivered through multiple vectors including email and compromised patch management infrastructure.
Vendor-detected malware name associated with the DarkSeoul activity; described elsewhere in the content as involving hard drive overwrites/wiping behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.