JitterDropper
A Rust/MSVC dropper fingerprinted by per-API sleep-jitter budgets
Overview
We have observed a new Rust/MSVC Windows dropper under active development since at least 2026-03-18 with nine builds observed across two variant lines. Currently the name is unknown so we will dubbing it JitterDropper
.
Variant I embeds the payload in .rdata
and runs a multi-pass decryption algorithm producing...
From a pattern analysis perspective, the article presents JQ as a sophisticated and adaptable piece of malware that is a significant threat to cybersecurity. The use of legitimate APIs and polymorphic code suggests that the creators have a deep understanding of how security software operates and are constantly evolving their tactics to stay one step ahead.
The targeting of government organizations in the Middle East indicates a potential geopolitical motive behind the malware's creation. However...