APT / THREAT GROUP

JARLEASH

2
aliases
Last seen:Jul 15, 2026

Intelligence Profile

According to Cisco Talos, JARLEASH is a JAVA-based backdoor deployed on attacker infrastructure and compromised systems with JAVA available, providing a web-based file management interface, FTP and SFTP servers, and a netcat server, with configuration comments written in Simplified Chinese.

Threat Analysis

JARLEASH is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.

Intelligence Reports Mentioning JARLEASH

External References

Quick Facts

TypeAPT / Threat Group
Aliases2

Also Known As

JARLEASHjar.jarleash

External Intelligence

Malpedia: jar.jarleash

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.