Skip to content

Malware

Akemi

According to VMRay, this malware family uses in interesting obfuscation technique: a trailing slash in its archive to confuse analysis tools.

Akemi is a Java malware family.

Background

VMRay notes that Akemi relies on an unusual obfuscation trick, adding a trailing slash to its archive to throw off analysis tools. It uses GitHub as its command-and-control channel and exfiltrates stolen data, including browser cookies, through Discord webhooks. The associated GitHub repositories have been active since mid-to-late 2024. The malware additionally tracks keyboard and mouse activity and captures screenshots.


Source: Malpedia (Fraunhofer FKIE).