Joanap is a Windows remote access trojan and peer-to-peer botnet malware family associated with the North Korean threat cluster tracked as HIDDEN COBRA and widely linked to Lazarus. It has been used since at least 2009 as second-stage malware, often in conjunction with the Brambul SMB worm, to establish and maintain compromised infrastructure for follow-on intrusion activity. Joanap provides operators with remote control of infected systems, including the ability to exfiltrate data, download and execute additional payloads, manage files and processes, and relay traffic through proxy functionality. Public reporting also describes Joanap as supporting botnet node management and peer-to-peer communications rather than relying solely on centralized command-and-control architecture.
On infected Windows hosts, Joanap has been observed using encrypted communications, including RC4-protected traffic, and listening for operator connections over commonly used service ports. Variants have been described as fully functional RATs capable of receiving multiple remote commands. In operational use, Joanap has been tied to campaigns targeting organizations globally, including victims in the United States and South Korea, with affected sectors including media, aerospace, financial, critical infrastructure, and manufacturing. It has been used to gain access to systems and preserve attacker-controlled footholds from which additional espionage or other malicious activity can be conducted.
Joanap is commonly delivered as a dropped payload by other HIDDEN COBRA tooling. High-confidence reporting links it to Brambul-enabled propagation, where the worm brute-forces SMB-accessible systems and installs Joanap as follow-on malware. Additional reporting indicates victims could also become infected through compromised websites and malicious email attachments. Joanap is therefore best understood as a Lazarus-linked Windows RAT used for persistent remote access, botnet operations, payload staging, proxying, and data theft in broader state-sponsored intrusion campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Alert (TA18-149A): HIDDEN COBRA – Joanap Backdoor Trojan and Brambul Server Message Block Worm
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The Justice Department today announced an extensive effort to map and further disrupt, through victim notifications, the Joanap botnet – a global network of numerous infected computers under the control of North Korean hackers... Computers infected with Joanap — known as “peers” or “bots” — became part of a network of compromised computers known as a botnet.
Analysis indicates the malware encodes data using Rivest Cipher 4 encryption to protect its communication with HIDDEN COBRA actors.
Joanap malware is a fully functional RAT that is able to receive multiple commands, which can be issued by HIDDEN COBRA actors remotely from a command and control server.
Joanap malware provides HIDDEN COBRA actors with the ability to exfiltrate data, drop and run secondary payloads, and initialize proxy communications on a compromised Windows device.
Joanap uses a decentralized peer-to-peer communication system, rather than a centralized mechanism to communicate with and control the peers, such as a command-and-control domain.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage peer-to-peer botnet/backdoor used to exfiltrate data, download and execute secondary payloads, and initialize proxy communications.
A second-stage Windows malware used to remotely access infected systems, gain root-level or near-total access, load additional malware, and enroll hosts into a decentralized peer-to-peer botnet.
Remote access trojan/backdoor that listens on port 443, uses RC4-encrypted C2 communications, logs victim IP/hostname/time, and enables exfiltration, command execution, proxying, and delivery of secondary payloads.
A two-stage remote access tool used to establish peer-to-peer communications and manage botnets. It can exfiltrate data, drop and execute secondary payloads, initialize proxy communications, and perform file, process, directory, and node management on compromised Windows systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.