Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AlienSpy was a Java-based remote access trojan (RAT) reported in 2015 as targeting both ordinary internet users and organizations. Reports described builds for Windows, Linux, Mac, and Android, and capabilities including surveillance, credential theft, file access, and remote control. Those findings are historical: they do not establish that AlienSpy is active today or that every sample had every capability.

What AlienSpy was—and how it fits the Adwind lineage

In an April 9, 2015 report, SecurityWeek, citing General Dynamics Fidelis Cybersecurity Solutions, described AlienSpy as a Java-based RAT and as a successor to Frutas, Adwind, and Unrecom. Kaspersky’s later account grouped AlienSpy with other names used across the broader lineage, including Frutas, jFrutas, Unrecom, Sockrat, JSocket, and jRat. Shared lineage is useful context, but it does not mean every variant was technically identical.

Check Point’s retrospective dates AlienSpy’s release to October 2014 and says activity was suspended around April 2015 after a Fidelis report. It describes JSocket, released in June 2015, as a later reincarnation. These are historical accounts, not evidence about current availability or activity.

What AlienSpy could do

The capabilities reported for AlienSpy included collecting system information, downloading and executing other malware, capturing webcam and microphone activity, monitoring the remote desktop, accessing files, logging keystrokes, and stealing browser passwords. Fidelis also reported sandbox detection, disabling security tools, TLS-protected command-and-control communications, and a modular plugin system that could be extended. These are reported capabilities, not a claim that each analyzed sample used all of them. [c001]

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

Kaspersky’s descriptions of remote control, data gathering, exfiltration, lateral movement, and downloaded plugins—including remote-control options and shell-command execution—refer to the broader Adwind family. Kaspersky’s February 8, 2016 FAQ says the malware could send system information, receive commands, and load plugins; those family-level observations should not automatically be assigned to every AlienSpy sample.

Why reports described it as cross-platform

AlienSpy was described as Java-based, with builds reported for Windows, Linux, Mac, and Android. Kaspersky likewise described the broader Java-based backdoor as running on Windows, Mac OS, Linux, and Android. Java can support software across operating systems, but a family’s platform claims and the format of a particular malicious file are separate questions.

That distinction matters for a JAR sample examined by Proofpoint after it was associated in media coverage with Alberto Nisman. Proofpoint noted that Android malware is typically delivered as an APK or native ARM binary, and that running a JAR on Android is not straightforward without a Java emulation engine. Researchers considered the sample more likely intended for a desktop and said it might have been downloaded to a phone inadvertently. They also said its relationship to Nisman’s death was unclear.

How it was delivered and who was targeted

Fidelis observed phishing emails framed around payments and orders. Citizen Lab’s report on Packrat documented AlienSpy implants sent as email attachments with a “.pdf.jar” extension from 2014 through early 2015. On Windows systems configured to hide known file extensions, a recipient might see the misleading “.pdf” portion and mistake the file for a PDF.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The 2015 AlienSpy report listed energy, government, financial services, and technology among sectors targeted by samples. Citizen Lab documented Packrat espionage involving journalists and public figures in the region, but said it could not verify a claim that Máximo Kirchner had been targeted. The reporting supports that AlienSpy was used in phishing and espionage contexts; it does not establish every alleged target or attribution.

Kaspersky’s victim and industry figures describe the Adwind platform across multiple variants, not AlienSpy alone. Its 2016 investigation analyzed nearly 200 spear-phishing examples to identify target industries and said victims ranged from people who launched malware after opportunistic attacks to specific organizations, most of them small and medium-sized businesses.

What the Adwind statistics do—and do not—show

Kaspersky Lab’s 2016 figures provide scale for the wider Adwind platform. They should not be presented as AlienSpy-only counts.

Figure What it represents
At least 443,000 private users and commercial and non-commercial organizations Targets of different Adwind malware versions between 2013 and 2016, according to Kaspersky Lab in 2016; not AlienSpy alone.
Nearly 200 spear-phishing examples Examples Kaspersky researchers analyzed in 2016 to identify industries targeted during the Adwind investigation; not a count of AlienSpy victims.
Around 1,800 users Kaspersky Lab’s estimate of platform users by the end of 2015, based on user activity and other observations; not a current user count.

Kaspersky’s investigation listed targets in manufacturing, finance, engineering, design, retail, government, shipping, telecommunications, software, education, food production, healthcare, media, and energy. That broad list belongs to the multi-variant Adwind investigation, not specifically to AlienSpy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Practical precautions for email and Java

The historical delivery reports support two sensible precautions: treat unexpected attachments cautiously, especially when a file name combines a document extension with another extension, and limit Java execution to sources an organization authorizes. Kaspersky’s dated enterprise guidance put the latter plainly: “We would like to encourage enterprises to review the purpose of using a Java platform and to disable it for all unauthorized sources.”

  • Verify unexpected payment- or order-related attachments through a separate, trusted channel before opening them.
  • Check the full filename and extension rather than relying on an icon or a visible “.pdf” suffix.
  • For organizations, review where Java is needed and restrict execution from unauthorized sources, as Kaspersky advised in its 2016 FAQ.

The cited reporting does not establish current detection rates or whether any particular security product blocks AlienSpy today.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.