APT / THREAT GROUP
JARLEASH
2
aliases
Last seen:Jul 15, 2026
Intelligence Profile
According to Cisco Talos, JARLEASH is a JAVA-based backdoor deployed on attacker infrastructure and compromised systems with JAVA available, providing a web-based file management interface, FTP and SFTP servers, and a netcat server, with configuration comments written in Simplified Chinese.
Threat Analysis
JARLEASH is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.
Intelligence Reports Mentioning JARLEASH
China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
SecurityWeek· Jul 8, 2026
External References
Quick Facts
TypeAPT / Threat Group
Aliases2
Also Known As
JARLEASHjar.jarleash
External Intelligence
Malpedia: jar.jarleashResearch Links
Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.