Skip to main content

Jupyter Trojan

Jupiter is a combined infostealer and backdoor sold on Russian hacking forums. Updated monthly, it will collect user browser information; and uses the legitimate Inno Script installer and PoshC2 framework services to avoid detection.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Jupiter is a combined infostealer and backdoor sold on Russian hacking forums. Updated monthly, it will collect user browser information; and uses the legitimate Inno Script installer and PoshC2 framework services to avoid detection.


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

First observed in May 2020, Jupyter is a modular backdoor primarily used to extract sensitive user information from web browsers. Sold on Russian-speaking hacking forums, it makes use of several legitimate applications and is updated monthly with new capabilities.


Delivery

Jupiter is delivered via phishing emails containing a ZIP file. This archive itself contains an EXE installer made using the legitimate Inno Script installation system. When opened, this installer drops two files in the Temp folder. The first file is a PowerShell script which will decrypt the other file when executed. The second file then drops two more files, a batch script and a .NET assembly, in a folder in the AppData directory. The batch script then decrypts and injects the .NET assembly containing the Jupiter client into memory.

Some Jupiter variants use the PoshC2 post-exploitation command and control (C2) framework to gain persistence by placing LNK files in the StartUp folder.


Activities

Once installed, the Jupiter client will collect user and system information before sending it to a C2 server. This information is then used to determine the version of Jupiter infostealer module sent to the client, which then injects the infostealer into a running process.

Information extracted by Jupyter's infostealer module includes:

  • autocomplete data
  • cookies
  • login information
  • form entries
  • browsing history

Collected information is then sent to a separate C2 server.


Remediation advice

To prevent and detect an infection, NHS Digital advises that:

  • Secure configurations are applied to all devices.
  • Security updates are applied at the earliest opportunity.
  • Tamper protection settings in security products are enabled where available.
  • Obsolete platforms are segregated from the rest of the network.
  • IT usage policies are reinforced by regular training to ensure all users know not to open unsolicited links or attachments.
  • Multi-factor authentication (MFA) and lockout policies are used where practicable, especially for administrative accounts.
  • Administrative accounts are only used for necessary purposes.
  • Remote administration services use strongly encrypted protocols and only accept connections from authorised users or locations.
  • Systems are continuously monitored, and unusual activity is investigated, so that a compromise of the network can be detected as early as possible.

Please note that the NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages.


Indicators of compromise

Network indicators

IP addresses

  • 45.135.232[.]131
  • 45.146.165[.]222
  • 45.146.165[.]219
  • 91.241.19[.]21

Domains

  • blackl1vesmatter[.]org
  • gogohid[.]com
  • mixblazerteam[.]com
  • on-offtrack[.]biz
  • spacetruck[.]biz
  • vincentolife[.]com
Host indicators

SHA1 hashes

  • 02a52b218756fa65e9fd8a9acb75202afd150e4c
  • 1478b1ead914f03d801087dc0b4cca07b19c7f53
  • 261ed0f6c7b5052a6f4275a2c4d3207e56333b05
  • 3854bc3263c1bf3e3a79c0310e1b972bcb17b8a5
  • 59488aa15eeb47cd0b024c8a117db82f1bc17a80
  • 8133304181d209cb302fbcdbf3965b0b5c7fa20c
  • 942c1b5eb8ea14e2fa0d0b83a296cf37c8efa688
  • aecd083118b9333133c2f43f85558730285ed292
  • b2ed7e45eec9afb74ffbfa90495824945b8a84c7
  • ce9d62978c8af736935af5ed1808bfc829cbb546
  • ea2b5b7bcc0efde95ef1daf91dcb1aa55e3458a9
  • f76e293d627c55eca18ce96e587fb8c6e37d8206

Last edited: 7 September 2021 12:39 pm