{"id":2356,"date":"2019-04-23T10:19:30","date_gmt":"2019-04-23T10:19:30","guid":{"rendered":"https:\/\/www.varutra.com\/blog\/?p=2068"},"modified":"2022-12-02T15:17:20","modified_gmt":"2022-12-02T09:47:20","slug":"joanap-and-brambul-malware","status":"publish","type":"post","link":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/","title":{"rendered":"Joanap and Brambul Malware"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/varutra-1a3b6.kxcdn.com\/wp-content\/uploads\/2019\/04\/Joanap-and-Brambul-Malware-1024x535.png\"  class=\"sh-overlay-item sh-table-cell ls-is-cached lazyloaded\" data-rel=\"lightcase\" title=\"Joanap and Brambul Malware - Varutra Consulting\"><\/p>\n<p style=\"text-align: left\">Joanap and Brambul Malware has come from North Korea that has infected numerous Microsoft Windows computers globally over the last decade. On 30<sup>th<\/sup>\u00a0January 2019 United States Department of Justice (DoJ) announced that, its effort to map and further disrupt a botnet that has tied to North Korea.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Overview of Joanap and Brambul Malware<\/strong><\/h3>\n<p>HIDDEN COBRA actors are using both Joanap and Brambul malware to target multiple victims globally\u00a0from 2009 and in the United States.<\/p>\n<p>The Hidden Cobra is the same hacking group that was allegedly associated with the WannaCry ransomware, the SWIFT Banking attack, as well as Sony Motion Pictures hacking.<\/p>\n<p>The Department of Homeland Security, DoJ and FBI further investigate and found that IP addresses and indicator of compromise (IOCs) used by North Korean government associated with two malware.<\/p>\n<ul>\n<li>Joanap, also known as Remote Access Tool (RAT)<\/li>\n<li>Brambul, also known as Server Message Block (SMB) worm.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3><strong>Description<\/strong><\/h3>\n<p>Joanap: It is a backdoor Trojan and also known as Remote access tool (RAT) is a type of malware, which lands on victims system used by government of North Korea. It enters with the help of SMB worm known as Brambul.<\/p>\n<p>Brambul: It also known as SMB worm is type of malware, which is malicious to Windows 32-bit SMB. It enters through SMB and dropped Joanap on the infected windows systems. As Joanap is, install in system it open a backdoor for its HIDDEN COBRA masterminds and giving them remote control over the network of infected systems.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Working<\/strong><\/h3>\n<h4><strong>Joanap<\/strong><\/h4>\n<p>It is a type of malware also known as remote access tool. It is a two-stage malware, which means another software drops it, in this case Brambul worm, which download Joanap in infected windows system. Joanap then establish peer-to-peer communications and used to manage botnets that are designed to enable other operations. After successfully installation of Joanap on Infected windows systems, it opens a backdoor for its HIDDEN COBRA actors with the ability to steal the data, exfiltration of data, drop and run secondary payloads and giving them remote control over the network of infected systems. It includes other notable functions file management, Process management, Creation and deletion of directories, Node management and initialize proxy communications on a compromised windows device.<\/p>\n<p>After executing Trojan, it creates the following files:<\/p>\n<ul>\n<li>%System%\\scardprv.dll<\/li>\n<li>%System%\\wcssvc.dll<\/li>\n<li>%System%\\mssscardprv.ax<\/li>\n<\/ul>\n<p>The Trojan then creates the following registry entries:<\/p>\n<ul>\n<li>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCardPrv\\Security\\\u201dSecurity\u201d = \u201c[HEXADECIMAL VALUE]\u201d<\/li>\n<li>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCardPrv\\Parameters\\\u201dServiceDll\u201d = \u201c%System%\\scardprv.dll\u201d<\/li>\n<li>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCardPrv\\\u201dType\u201d = \u201c20\u201d<\/li>\n<li>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCardPrv\\\u201dStart\u201d = \u201c2\u201d<\/li>\n<li>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCardPrv\\\u201dObjectName\u201d = \u201cLocalSystem\u201d<\/li>\n<li>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCardPrv\\\u201dImagePath\u201d = \u201c%System%\\svchost.exe -k SCardPrv\u201d<\/li>\n<li>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCardPrv\\\u201dErrorControl\u201d = \u201c1\u201d<\/li>\n<li>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SCardPrv\\\u201dDisplayName\u201d = \u201cSmartCard Protector\u201d<\/li>\n<\/ul>\n<p>Further analysing and investigating, found that the malware encode data using RC4 cipher encryption to its communication with HIDDEN COBRA actors. After Joanap Installed, the malware creates the log entry within the window system directory in a file name as mssscardprv.ax. Which uses by HIDDEN COBRA actors to capture and store victim\u2019s sensitive information use.<\/p>\n<p>&nbsp;<\/p>\n<h4><strong>Brambul<\/strong><\/h4>\n<p>It is a type of malware also known as SMB worm, which is malicious to Windows 32-bit SMB that functions as a service dynamic library file or a portable executable file get dropped and installed into victims systems by dropper malware. It enters through SMB and dropped Joanap on the infected windows systems. After successful installation, the malware established contact with victims systems and IP addresses on victims local subnets.<\/p>\n<p>A successful attack lead malware to gain unauthorized access via the SMB protocol (Port no. 445 and 139). It gains unauthorized access by launching a brute-force password using a list of known and common passwords. After successfully bypass login, the malware generates random IP addresses for further attacks. It communicates information about victims systems to HIDDEN COBRA actors using malicious email addresses. This information includes of Sensitive Information, IP address and hostname, as well as the username and password of each victims system.<\/p>\n<p>It identified the following built-in-functions for remote operations:<\/p>\n<ul>\n<li>Harvesting system information.<\/li>\n<li>Accepting command-line arguments.<\/li>\n<li>It generates and executes a suicide script.<\/li>\n<li>It propagates across the network using SMB.<\/li>\n<li>Bypass SMB login credential by Brute forcing<\/li>\n<li>Creating Simple Mail Transport Protocol and used to the email messages containing target host system information.<\/li>\n<\/ul>\n<p>The U.S. Government analyse the infrastructure used by Joanap malware and identified 87 compromised network nodes. The following countries are where the infected IP addresses are registered are as follows:<\/p>\n<table width=\"0\">\n<tbody>\n<tr>\n<td width=\"154\">Argentina<\/td>\n<td width=\"153\">Egypt<\/td>\n<td width=\"154\">Spain<\/td>\n<\/tr>\n<tr>\n<td width=\"154\">Belgium<\/td>\n<td width=\"153\">India<\/td>\n<td width=\"154\">Sri Lanka<\/td>\n<\/tr>\n<tr>\n<td width=\"154\">Brazil<\/td>\n<td width=\"153\">Iran<\/td>\n<td width=\"154\">Sweden<\/td>\n<\/tr>\n<tr>\n<td width=\"154\">Cambodia<\/td>\n<td width=\"153\">Jordan<\/td>\n<td width=\"154\">Taiwan<\/td>\n<\/tr>\n<tr>\n<td width=\"154\">China<\/td>\n<td width=\"153\">Pakistan<\/td>\n<td width=\"154\">Tunisia<\/td>\n<\/tr>\n<tr>\n<td width=\"154\">Colombia<\/td>\n<td width=\"153\">Saudi Arabia<\/td>\n<td width=\"154\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3><strong><br \/>\nImpact of Joanap and Brambul Malware<\/strong><\/h3>\n<ul>\n<li>Joanap is a malicious Trojan virus, which attacks remote computers. It opens backdoors entry for remote attackers to provide access on user\u2019s computer.<\/li>\n<li>Joanap is a malicious program, which has developed by cybercriminals to gain illegal income.<\/li>\n<li>Once getting control over the system, Joanap exhibits unpreventable behaviour. It asks to do a fake update of already installed programs or software in the system.<\/li>\n<li>It slows down system processing and interrupts normal functionality of Computer systems, it also disables task manager, control panel, firewalls etc.<\/li>\n<li>It leaves a bad impact on web browsers like Chrome\/IE\/Firefox to do illegal tasks. It changes the default setting to redirect users to unknown sites and replaces the original homepage and new tab with its fake one<\/li>\n<li>It monitors activities of users such as session ids, browsing history, Downloads, bookmarks, search queries, cookies, etc. and gather all credential and personal information to perform cybercrime and earn money.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3><strong>Mitigation<\/strong><\/h3>\n<ul>\n<li>Attacker target vulnerable applications and operating systems. Up-todate operating systems and software with the latest patches, patching with latest updates reduce the risk of exploitation available to an attacker.<\/li>\n<li>Use a firewall to block all incoming connections from the Internet that are hazardous for organization and should not be publicly available.<\/li>\n<li>Scan all the software downloaded from the internet before executing and maintain up to date antivirus software.<\/li>\n<li>Deny all incoming connections if it is not required and only allow services you explicitly want to offer to the outside world.<\/li>\n<li>Disable printers, files and sharing service, If not required by the organization.<\/li>\n<li>If services are required, use complex passwords as it makes it difficult to crack.<\/li>\n<li>Do user awareness programme, <a href=\"https:\/\/www.varutra.com\/cyber-security-training\/corporate-training\/\">train your employee<\/a> and organization not to open email or messages attachments unless they are expecting.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3><strong>References:<\/strong><\/h3>\n<p><a href=\"https:\/\/thehackernews.com\/2019\/01\/north-korea-hacker.html\">https:\/\/thehackernews.com\/2019\/01\/north-korea-hacker.html<\/a><\/p>\n<p><a href=\"https:\/\/www.symantec.com\/security-center\/writeup\/2015-092507-0410-99#removal\">https:\/\/www.symantec.com\/security-center\/writeup\/2015-092507-0410-99#removal<\/a><\/p>\n<h3>Author,<\/h3>\n<div dir=\"ltr\"><span style=\"font-size: small\"><strong>Saksham\u00a0Jaiswal<\/strong><\/span><\/div>\n<p><em>Attack &amp; PenTest Team<\/em><\/p>\n<p><em>Varutra Consulting<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Joanap and Brambul Malware has come from North Korea that has infected numerous Microsoft Windows computers globally over the last decade. On 30th\u00a0January 2019 United&#8230;<\/p>\n","protected":false},"author":3,"featured_media":18123,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[266,273,280],"tags":[247,248,249,250],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.6.3 - aioseo.com -->\n\t\t<meta name=\"description\" content=\"Joanap and Brambul Malware has come from North Korea that has infected numerous Microsoft Windows computers globally. Know its impact &amp; mitigation measures.\" \/>\n\t\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t\t<link rel=\"canonical\" href=\"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.6.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Varutra Consulting\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Joanap and Brambul Malware Overview, Impact, &amp; Mitigation\" \/>\n\t\t<meta property=\"og:description\" content=\"Joanap and Brambul Malware has come from North Korea that has infected numerous Microsoft Windows computers globally. Know its impact &amp; mitigation measures.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/04\/Joanap-and-Brambul-Malware.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/04\/Joanap-and-Brambul-Malware.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"627\" \/>\n\t\t<meta property=\"article:section\" content=\"Security Advisory\" \/>\n\t\t<meta property=\"article:tag\" content=\"brambul malware\" \/>\n\t\t<meta property=\"article:tag\" content=\"hidden cobra\" \/>\n\t\t<meta property=\"article:tag\" content=\"joanap malware\" \/>\n\t\t<meta property=\"article:tag\" content=\"north korea joanap and brambul\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-04-23T10:19:30+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-02T09:47:20+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Joanap and Brambul Malware Overview, Impact, &amp; Mitigation\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Joanap and Brambul Malware has come from North Korea that has infected numerous Microsoft Windows computers globally. Know its impact &amp; mitigation measures.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/04\/Joanap-and-Brambul-Malware.png\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"kalpadmin\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/joanap-and-brambul-malware\\\/#article\",\"name\":\"Joanap and Brambul Malware Overview, Impact, & Mitigation\",\"headline\":\"Joanap and Brambul Malware\",\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2019\\\/04\\\/Joanap-and-Brambul-Malware.png\",\"width\":1200,\"height\":627,\"caption\":\"Joanap and Brambul Malware\"},\"datePublished\":\"2019-04-23T10:19:30+05:30\",\"dateModified\":\"2022-12-02T15:17:20+05:30\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/joanap-and-brambul-malware\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/joanap-and-brambul-malware\\\/#webpage\"},\"articleSection\":\"Security Advisory, Security Best Practices, Viruses &amp; Malware, Brambul malware, HIDDEN COBRA, Joanap malware, North korea Joanap and brambul\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/joanap-and-brambul-malware\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"nextItem\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/joanap-and-brambul-malware\\\/#listItem\"},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/joanap-and-brambul-malware\\\/#listItem\",\"position\":2,\"name\":\"Joanap and Brambul Malware\",\"previousItem\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#listItem\"}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\",\"name\":\"Varutra\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Varutra-Found-e1612984024606.jpg\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/joanap-and-brambul-malware\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/joanap-and-brambul-malware\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/\",\"name\":\"kalpadmin\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/joanap-and-brambul-malware\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d69b4bf504d3e2e3c6ad0c424e16bcb2?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"kalpadmin\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/joanap-and-brambul-malware\\\/#webpage\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/joanap-and-brambul-malware\\\/\",\"name\":\"Joanap and Brambul Malware Overview, Impact, & Mitigation\",\"description\":\"Joanap and Brambul Malware has come from North Korea that has infected numerous Microsoft Windows computers globally. Know its impact & mitigation measures.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/joanap-and-brambul-malware\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2019\\\/04\\\/Joanap-and-Brambul-Malware.png\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/joanap-and-brambul-malware\\\/#mainImage\",\"width\":1200,\"height\":627,\"caption\":\"Joanap and Brambul Malware\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/joanap-and-brambul-malware\\\/#mainImage\"},\"datePublished\":\"2019-04-23T10:19:30+05:30\",\"dateModified\":\"2022-12-02T15:17:20+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"name\":\"Varutra Consulting\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Joanap and Brambul Malware Overview, Impact, &amp; Mitigation<\/title>\n\n","aioseo_head_json":{"title":"Joanap and Brambul Malware Overview, Impact, & Mitigation","description":"Joanap and Brambul Malware has come from North Korea that has infected numerous Microsoft Windows computers globally. Know its impact & mitigation measures.","canonical_url":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"og:locale":"en_US","og:site_name":"Varutra Consulting","og:type":"article","og:title":"Joanap and Brambul Malware Overview, Impact, &amp; Mitigation","og:description":"Joanap and Brambul Malware has come from North Korea that has infected numerous Microsoft Windows computers globally. Know its impact &amp; mitigation measures.","og:url":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/","og:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/04\/Joanap-and-Brambul-Malware.png","og:image:secure_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/04\/Joanap-and-Brambul-Malware.png","og:image:width":"1200","og:image:height":"627","article:section":"Security Advisory","article:tag":["brambul malware","hidden cobra","joanap malware","north korea joanap and brambul"],"article:published_time":"2019-04-23T10:19:30+00:00","article:modified_time":"2022-12-02T09:47:20+00:00","twitter:card":"summary_large_image","twitter:title":"Joanap and Brambul Malware Overview, Impact, &amp; Mitigation","twitter:description":"Joanap and Brambul Malware has come from North Korea that has infected numerous Microsoft Windows computers globally. Know its impact &amp; mitigation measures.","twitter:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/04\/Joanap-and-Brambul-Malware.png","twitter:label1":"Written by","twitter:data1":"kalpadmin","twitter:label2":"Est. reading time","twitter:data2":"6 minutes","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/#article","name":"Joanap and Brambul Malware Overview, Impact, & Mitigation","headline":"Joanap and Brambul Malware","author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2019\/04\/Joanap-and-Brambul-Malware.png","width":1200,"height":627,"caption":"Joanap and Brambul Malware"},"datePublished":"2019-04-23T10:19:30+05:30","dateModified":"2022-12-02T15:17:20+05:30","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/#webpage"},"isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/#webpage"},"articleSection":"Security Advisory, Security Best Practices, Viruses &amp; Malware, Brambul malware, HIDDEN COBRA, Joanap malware, North korea Joanap and brambul"},{"@type":"BreadcrumbList","@id":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/#listItem","position":1,"name":"Home","item":"https:\/\/www.varutra.com\/varutravrt3\/","nextItem":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/#listItem"},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/#listItem","position":2,"name":"Joanap and Brambul Malware","previousItem":"https:\/\/www.varutra.com\/varutravrt3\/#listItem"}]},{"@type":"Organization","@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization","name":"Varutra","url":"https:\/\/www.varutra.com\/varutravrt3\/","logo":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/Varutra-Found-e1612984024606.jpg","@id":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/#organizationLogo"},"image":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author","url":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/","name":"kalpadmin","image":{"@type":"ImageObject","@id":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/d69b4bf504d3e2e3c6ad0c424e16bcb2?s=96&d=mm&r=g","width":96,"height":96,"caption":"kalpadmin"}},{"@type":"WebPage","@id":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/#webpage","url":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/","name":"Joanap and Brambul Malware Overview, Impact, & Mitigation","description":"Joanap and Brambul Malware has come from North Korea that has infected numerous Microsoft Windows computers globally. Know its impact & mitigation measures.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#website"},"breadcrumb":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/#breadcrumblist"},"author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"creator":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2019\/04\/Joanap-and-Brambul-Malware.png","@id":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/#mainImage","width":1200,"height":627,"caption":"Joanap and Brambul Malware"},"primaryImageOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/#mainImage"},"datePublished":"2019-04-23T10:19:30+05:30","dateModified":"2022-12-02T15:17:20+05:30"},{"@type":"WebSite","@id":"https:\/\/www.varutra.com\/varutravrt3\/#website","url":"https:\/\/www.varutra.com\/varutravrt3\/","name":"Varutra Consulting","description":"Secure your digital world with our Cybersecurity services.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"}}]}},"aioseo_meta_data":{"post_id":"2356","title":"Joanap and Brambul Malware Overview, Impact, &amp; Mitigation&nbsp;","description":"Joanap and Brambul Malware has come from North Korea that has infected numerous Microsoft Windows computers globally. Know its impact &amp; mitigation measures.","keywords":[],"keyphrases":"{\"focus\":{\"keyphrase\":\"Joanap and Brambul Malware\",\"score\":80,\"analysis\":{\"keyphraseInTitle\":{\"title\":\"Focus keyphrase in SEO title\",\"description\":\"Focus keyphrase found in SEO title.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseInDescription\":{\"title\":\"Focus keyphrase in meta description\",\"description\":\"Focus keyphrase found in meta description.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseLength\":{\"title\":\"Focus keyphrase length\",\"description\":\"Good job!\",\"score\":9,\"maxScore\":9,\"error\":0,\"length\":4},\"keyphraseInURL\":{\"title\":\"Focus keyphrase in URL\",\"description\":\"Focus keyphrase used in the URL.\",\"score\":5,\"maxScore\":5,\"error\":0},\"keyphraseInIntroduction\":{\"title\":\"Focus keyphrase in introduction\",\"description\":\"Your Focus keyphrase appears in the first paragraph. Well done!\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseInSubHeadings\":{\"title\":\"Focus keyphrase in Subheadings\",\"description\":\"Use more focus keyphrases in your H2 and H3 subheadings!\",\"score\":3,\"maxScore\":9,\"error\":1},\"keyphraseInImageAlt\":{\"title\":\"Focus keyphrase in image alt attributes\",\"description\":\"Focus keyphrase not found in image alt attribute(s). Add an image with your Focus keyphrase as alt text.\",\"score\":3,\"maxScore\":9,\"error\":1}}},\"additional\":[{\"keyphrase\":\"Brambul Malware\",\"score\":83,\"analysis\":{\"keyphraseInDescription\":{\"title\":\"Keyphrase in meta description\",\"description\":\"Keyphrase found in meta description.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseLength\":{\"title\":\"Keyphrase length\",\"description\":\"Good job!\",\"score\":9,\"maxScore\":9,\"error\":0,\"length\":2},\"keyphraseInIntroduction\":{\"title\":\"Keyphrase in introduction\",\"description\":\"Your Keyphrase appears in the first paragraph. Well done!\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseInImageAlt\":{\"title\":\"Keyphrase in image alt attributes\",\"description\":\"Keyphrase not found in image alt attribute(s). Add an image with your Keyphrase as alt text.\",\"score\":3,\"maxScore\":9,\"error\":1}}},{\"keyphrase\":\"Joanap\",\"score\":83,\"analysis\":{\"keyphraseInDescription\":{\"title\":\"Keyphrase in meta description\",\"description\":\"Keyphrase found in meta description.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseLength\":{\"title\":\"Keyphrase length\",\"description\":\"Good job!\",\"score\":9,\"maxScore\":9,\"error\":0,\"length\":1},\"keyphraseInIntroduction\":{\"title\":\"Keyphrase in introduction\",\"description\":\"Your Keyphrase appears in the first paragraph. Well done!\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseInImageAlt\":{\"title\":\"Keyphrase in image alt attributes\",\"description\":\"Keyphrase not found in image alt attribute(s). Add an image with your Keyphrase as alt text.\",\"score\":3,\"maxScore\":9,\"error\":1}}},{\"keyphrase\":\"Malware\",\"score\":83,\"analysis\":{\"keyphraseInDescription\":{\"title\":\"Keyphrase in meta description\",\"description\":\"Keyphrase found in meta description.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseLength\":{\"title\":\"Keyphrase length\",\"description\":\"Good job!\",\"score\":9,\"maxScore\":9,\"error\":0,\"length\":1},\"keyphraseInIntroduction\":{\"title\":\"Keyphrase in introduction\",\"description\":\"Your Keyphrase appears in the first paragraph. Well done!\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseInImageAlt\":{\"title\":\"Keyphrase in image alt attributes\",\"description\":\"Keyphrase not found in image alt attribute(s). Add an image with your Keyphrase as alt text.\",\"score\":3,\"maxScore\":9,\"error\":1}}}]}","primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"featured","og_image_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2019\/04\/Joanap-and-Brambul-Malware.png","og_image_width":"1200","og_image_height":"627","og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Security Advisory","og_article_tags":[],"twitter_use_og":true,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"open_ai":null,"created":"2021-10-27 15:16:26","updated":"2022-12-02 09:47:52"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\/category\/security-advisory\/\" title=\"Security Advisory\">Security Advisory<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tJoanap and Brambul Malware\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.varutra.com\/varutravrt3"},{"label":"Security Advisory","link":"https:\/\/www.varutra.com\/varutravrt3\/category\/security-advisory\/"},{"label":"Joanap and Brambul Malware","link":"https:\/\/www.varutra.com\/varutravrt3\/joanap-and-brambul-malware\/"}],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/2356"}],"collection":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/comments?post=2356"}],"version-history":[{"count":6,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/2356\/revisions"}],"predecessor-version":[{"id":20340,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/2356\/revisions\/20340"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media\/18123"}],"wp:attachment":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media?parent=2356"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/categories?post=2356"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/tags?post=2356"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}