Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteAlienSpy was a Java-based remote access trojan (RAT) reported in 2015 as targeting both ordinary internet users and organizations. Reports described builds for Windows, Linux, Mac, and Android, and capabilities including surveillance, credential theft, file access, and remote control. Those findings are historical: they do not establish that AlienSpy is active today or that every sample had every capability.
What AlienSpy was—and how it fits the Adwind lineage
In an April 9, 2015 report, SecurityWeek, citing General Dynamics Fidelis Cybersecurity Solutions, described AlienSpy as a Java-based RAT and as a successor to Frutas, Adwind, and Unrecom. Kaspersky’s later account grouped AlienSpy with other names used across the broader lineage, including Frutas, jFrutas, Unrecom, Sockrat, JSocket, and jRat. Shared lineage is useful context, but it does not mean every variant was technically identical.
Check Point’s retrospective dates AlienSpy’s release to October 2014 and says activity was suspended around April 2015 after a Fidelis report. It describes JSocket, released in June 2015, as a later reincarnation. These are historical accounts, not evidence about current availability or activity.
What AlienSpy could do
The capabilities reported for AlienSpy included collecting system information, downloading and executing other malware, capturing webcam and microphone activity, monitoring the remote desktop, accessing files, logging keystrokes, and stealing browser passwords. Fidelis also reported sandbox detection, disabling security tools, TLS-protected command-and-control communications, and a modular plugin system that could be extended. These are reported capabilities, not a claim that each analyzed sample used all of them. [c001]
#1 Best Overall
Kaspersky’s descriptions of remote control, data gathering, exfiltration, lateral movement, and downloaded plugins—including remote-control options and shell-command execution—refer to the broader Adwind family. Kaspersky’s February 8, 2016 FAQ says the malware could send system information, receive commands, and load plugins; those family-level observations should not automatically be assigned to every AlienSpy sample.
Why reports described it as cross-platform
AlienSpy was described as Java-based, with builds reported for Windows, Linux, Mac, and Android. Kaspersky likewise described the broader Java-based backdoor as running on Windows, Mac OS, Linux, and Android. Java can support software across operating systems, but a family’s platform claims and the format of a particular malicious file are separate questions.
That distinction matters for a JAR sample examined by Proofpoint after it was associated in media coverage with Alberto Nisman. Proofpoint noted that Android malware is typically delivered as an APK or native ARM binary, and that running a JAR on Android is not straightforward without a Java emulation engine. Researchers considered the sample more likely intended for a desktop and said it might have been downloaded to a phone inadvertently. They also said its relationship to Nisman’s death was unclear.
How it was delivered and who was targeted
Fidelis observed phishing emails framed around payments and orders. Citizen Lab’s report on Packrat documented AlienSpy implants sent as email attachments with a “.pdf.jar” extension from 2014 through early 2015. On Windows systems configured to hide known file extensions, a recipient might see the misleading “.pdf” portion and mistake the file for a PDF.
The 2015 AlienSpy report listed energy, government, financial services, and technology among sectors targeted by samples. Citizen Lab documented Packrat espionage involving journalists and public figures in the region, but said it could not verify a claim that Máximo Kirchner had been targeted. The reporting supports that AlienSpy was used in phishing and espionage contexts; it does not establish every alleged target or attribution.
Kaspersky’s victim and industry figures describe the Adwind platform across multiple variants, not AlienSpy alone. Its 2016 investigation analyzed nearly 200 spear-phishing examples to identify target industries and said victims ranged from people who launched malware after opportunistic attacks to specific organizations, most of them small and medium-sized businesses.
What the Adwind statistics do—and do not—show
Kaspersky Lab’s 2016 figures provide scale for the wider Adwind platform. They should not be presented as AlienSpy-only counts.
| Figure | What it represents |
|---|---|
| At least 443,000 private users and commercial and non-commercial organizations | Targets of different Adwind malware versions between 2013 and 2016, according to Kaspersky Lab in 2016; not AlienSpy alone. |
| Nearly 200 spear-phishing examples | Examples Kaspersky researchers analyzed in 2016 to identify industries targeted during the Adwind investigation; not a count of AlienSpy victims. |
| Around 1,800 users | Kaspersky Lab’s estimate of platform users by the end of 2015, based on user activity and other observations; not a current user count. |
Kaspersky’s investigation listed targets in manufacturing, finance, engineering, design, retail, government, shipping, telecommunications, software, education, food production, healthcare, media, and energy. That broad list belongs to the multi-variant Adwind investigation, not specifically to AlienSpy.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Best Value
Practical precautions for email and Java
The historical delivery reports support two sensible precautions: treat unexpected attachments cautiously, especially when a file name combines a document extension with another extension, and limit Java execution to sources an organization authorizes. Kaspersky’s dated enterprise guidance put the latter plainly: “We would like to encourage enterprises to review the purpose of using a Java platform and to disable it for all unauthorized sources.”
- Verify unexpected payment- or order-related attachments through a separate, trusted channel before opening them.
- Check the full filename and extension rather than relying on an icon or a visible “.pdf” suffix.
- For organizations, review where Java is needed and restrict execution from unauthorized sources, as Kaspersky advised in its 2016 FAQ.
The cited reporting does not establish current detection rates or whether any particular security product blocks AlienSpy today.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

