Skip to main content

Backdoor:Python/Janicab.A

Classification

Category:

Malware

Platform:

Python

Type:

Backdoor

Aliases:

  • OSX/Janicab.A
  • Trojan.Janicab
  • Troj/Janicab-A

Summary

Backdoor:Python/Janicab.A is capable of running on both Windows and OS X machines; once installed it continuously takes screenshots and records audio, then forwards these to its command and control server.

Removal

Technical Details

Janicab.A is written in Python and is capable of running on machines with either the Windows or OS X operating systems.

When executed, the malware displays a decoy document; in the meantime, it installs itself in the background and connects to a remote site in order to get the address of its command and control (C&C) server.

While active, the malware continuously uses a third-party plugin to take screenshots and record audio, then uploads these to the C&C server. It also constantly checks for additional commands to execute from the C&C server.

The malware is notable for being signed with an Apple Developer ID and for using the right-to-left override (RLO) feature of the bi-directional text encoding system to hide the real extensions of executable files.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.