• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    Tanaka

    Tanaka Dominates Data Leak Landscape With 25 Leak Posts

    Employment scams

    FBI, LinkedIn Warn Job Seekers of Employment Scams and Exploitation

    Hermes AI Agent

    Hermes AI Agent Used in Cyberattack Targeting Thailand Finance Ministry

    Origin Energy data breach

    Origin Energy Data Breach Affects 900,000 Current and Former Customers

    ZTNA

    ZTNA Emerges as VPN Security Risks Put Federal Networks on Alert

    Tribeca Film Festival Data Breach

    Angelina Jolie, Robert De Niro Among Hollywood Stars Hit by Tribeca Data Leak

    GitLab vulnerability

    Two Old Oj Flaws Chained to Trigger GitLab Remote Code Execution

    Minnesota Medicaid fraud

    Four Men Admit to $2.2M Medicaid Fraud Scheme Using ChatGPT

    Gentlemen ransomware group

    How the Gentlemen Ransomware Group Built a Multi-Region Attack Machine in H1 2026

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    India online safety rules

    India Tightens Social Media Rules to Protect Children Online

    global crypto investment scam

    Dutch Police Arrest Key Suspect in €100M Global Crypto Investment Scam

    Australia-India PACTS

    Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

    FBI Warns of Malicious Traffic

    FBI Warns of a Hidden Web Tactic Fueling Phishing and Ransomware

    Ukraine Joins EU Cybersecurity Reserve

    What Ukraine’s Entry Into the EU Cybersecurity Reserve Means

    UK social media ban

    UK Social Media Ban for Under-16s Could Take Effect by Spring 2027

    Ransomware Preparedness

    Ransomware Preparedness Must Be a Boardroom Priority: NCSC Chief

    AI legal assistants

    AI Heads to UK Courts, Bringing New Cybersecurity and Governance Challenges

    VerdantBamboo

    China’s VerdantBamboo Experimented With Three Re-Entries and Three Malware in a Company Network

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Australia-India PACTS

    Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

    Sunil Varkey

    Sunil Varkey Joins Hexaware Technologies as EVP & CISO

    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI, AI-assisted Cyberattacks

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    Tanaka

    Tanaka Dominates Data Leak Landscape With 25 Leak Posts

    Employment scams

    FBI, LinkedIn Warn Job Seekers of Employment Scams and Exploitation

    Hermes AI Agent

    Hermes AI Agent Used in Cyberattack Targeting Thailand Finance Ministry

    Origin Energy data breach

    Origin Energy Data Breach Affects 900,000 Current and Former Customers

    ZTNA

    ZTNA Emerges as VPN Security Risks Put Federal Networks on Alert

    Tribeca Film Festival Data Breach

    Angelina Jolie, Robert De Niro Among Hollywood Stars Hit by Tribeca Data Leak

    GitLab vulnerability

    Two Old Oj Flaws Chained to Trigger GitLab Remote Code Execution

    Minnesota Medicaid fraud

    Four Men Admit to $2.2M Medicaid Fraud Scheme Using ChatGPT

    Gentlemen ransomware group

    How the Gentlemen Ransomware Group Built a Multi-Region Attack Machine in H1 2026

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    India online safety rules

    India Tightens Social Media Rules to Protect Children Online

    global crypto investment scam

    Dutch Police Arrest Key Suspect in €100M Global Crypto Investment Scam

    Australia-India PACTS

    Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

    FBI Warns of Malicious Traffic

    FBI Warns of a Hidden Web Tactic Fueling Phishing and Ransomware

    Ukraine Joins EU Cybersecurity Reserve

    What Ukraine’s Entry Into the EU Cybersecurity Reserve Means

    UK social media ban

    UK Social Media Ban for Under-16s Could Take Effect by Spring 2027

    Ransomware Preparedness

    Ransomware Preparedness Must Be a Boardroom Priority: NCSC Chief

    AI legal assistants

    AI Heads to UK Courts, Bringing New Cybersecurity and Governance Challenges

    VerdantBamboo

    China’s VerdantBamboo Experimented With Three Re-Entries and Three Malware in a Company Network

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Australia-India PACTS

    Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

    Sunil Varkey

    Sunil Varkey Joins Hexaware Technologies as EVP & CISO

    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI, AI-assisted Cyberattacks

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Reputational Hijacking with JamPlus: A New Technique to Bypass Smart App Control (SAC)

Ashish Khaitan by Ashish Khaitan
September 9, 2024
in Firewall Daily, Cyber News, Dark Web News
0
JamPlus phishing campaign
730
SHARES
4.1k
VIEWS
Share on LinkedInShare on Twitter

Recent research by Cyble Research and Intelligence Labs (CRIL) has revealed a new phishing campaign that capitalizes on the popularity of CapCut, a video editing tool developed by Bytedance. This campaign employs a sophisticated reputational hijacking technique utilizing JamPlus to bypass Smart App Control (SAC) and deploy malicious payloads.

CapCut has gained significant traction as a video editing application, making it an attractive target for threat actors (TAs) seeking to exploit its reputation for malicious purposes. The latest campaign, identified by CRIL, reveals how attackers use a phishing site masquerading as a CapCut download page to trick users into installing malware.

Overview of the CapCut Phishing Campaign

In this campaign, TAs leverage JamPlus, a build utility, to carry out their attack. This technique, known as reputational hijacking with JamPlus, involves embedding a legitimate CapCut application within a malicious package to bypass traditional security measures. The attackers’ approach highlights an evolving trend in cyberattacks aimed at circumventing security controls and increasing the efficacy of malicious campaigns.

CapCut Phishing Campaign
Infection Chain (Source: Cyble)

The attack unfolds through a multi-stage process designed to evade detection. It begins when a user downloads a malicious package from a phishing site posing as a CapCut installer. This package contains a legitimate CapCut application, the JamPlus build utility, and a malicious “.lua” script.

When the user runs the CapCut application, it inadvertently triggers the JamPlus build utility. This utility then executes the malicious “.lua” script, which silently downloads and executes a batch file from a remote server. The use of fileless techniques is a key element in this attack, aiming to avoid traditional security mechanisms and remain undetected.

Technical Details of the JamPlus Campaign 

The phishing site presents a convincing façade of a CapCut download page, prompting users to click on a “Download” button. This action initiates the download of an archive named “CapCut_{random number}_Installer” from a URL like “hxxps://www[.]dropbox[.]com/scl/fi/6se0kgmo7sbngtdf8r11x/CapCut_7376550521366298640_installer.zip?rlkey=7fxladl3fdhpne6p7buz48kcl&st=pzxtrcqc&dl=1”.

Upon extraction, the user encounters a file that appears to be a CapCut installer, but it actually includes the legitimate CapCut application along with hidden files for malicious activities. These hidden files contain the JamPlus build utility and a malicious “.lua” script.

By default, the CapCut shortcut on the desktop runs the CapCut application located at “C:\Users<User_Name>\AppData\Local\CapCut\Apps\capcut.exe”. In this attack, however, the JamPlus build utility is renamed to “capcut.exe” to exploit the application’s reputation and execute the malicious script.

Despite an initial failure to execute due to incorrect naming, renaming the file to “capcut.exe” successfully triggers the JamPlus build utility. This utility then reads from a “.jam” file configured to identify and run the malicious “.lua” script.

The “.lua” script downloads a batch file from a remote server and executes it. This batch file performs several actions:

  • Downloads a file named “WindowSafety.bat” from “hxxps://raw[.]githubusercontent.com/LoneNone1807/batman/main/startup” and saves it in the startup folder to ensure it runs on the next system reboot.
  • Downloads a ZIP file named “Document.zip” from “hxxps://github[.]com/LoneNone1807/batman/raw/main/Document.zip” and extracts it to “C:\Users\Public\Document”.
  • Executes a Python script named “sim.py” from the extracted folder.

The NodeStealer Payload

The Python script retrieves and decodes base64-encoded data from a remote server, executing the resulting payload directly in memory. This payload is a variant of NodeStealer, a sophisticated malware designed to steal a wide array of sensitive data from the victim’s machine, including login credentials, cookies, credit card information, and data from browser extensions and applications.

NodeStealer’s exfiltration method involves sending the stolen information via Telegram, adding another layer of obfuscation to the attack. The campaign has been traced back to threat actors based in Vietnam.

This technique of reputational hijacking with JamPlus is not isolated. Similar tactics have been observed in other campaigns, such as those using a legitimately signed Postman application.

JamPlus
Postman application used in a similar campaign (Source: Cyble)

This broader pattern indicates a growing trend where TAs leverage trusted applications and tools to mask their malicious activities and bypass security systems.

Conclusion

The use of reputational hijacking with JamPlus to bypass Smart App Control (SAC) represents a significant advancement in attack strategies. By incorporating legitimate applications and building utilities into their schemes, threat actors enhance their ability to evade detection and execute sophisticated attacks.

The deployment of NodeStealer in this campaign underscores the growing complexity of cyber threats and the challenges faced by cybersecurity professionals.

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: CapCut PhishingJamPlusphishing siteSACSmart App ControlThe Cyber ExpressThe Cyber Express News
Previous Post

Iranian Vice President Highlights Fuel Station Vulnerability to Cyberattacks

Next Post

Two Arrested by FBI for Credit Card Fraud Could Face 20-Yrs Prison

Next Post
WWH-Club credit card

Two Arrested by FBI for Credit Card Fraud Could Face 20-Yrs Prison

Q1 2026 Threat Reports

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

Tanaka
Firewall Daily

Tanaka Dominates Data Leak Landscape With 25 Leak Posts

July 28, 2026
Employment scams
Cyber News

FBI, LinkedIn Warn Job Seekers of Employment Scams and Exploitation

July 28, 2026
Hermes AI Agent
Cyber News

Hermes AI Agent Used in Cyberattack Targeting Thailand Finance Ministry

July 28, 2026
Origin Energy data breach
Firewall Daily

Origin Energy Data Breach Affects 900,000 Current and Former Customers

July 28, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information