JackOfHearts

Description

(Kaspersky) JackOfHearts is the dropper associated with QueenOfHearts: its role is to write the malware somewhere on the disk (for instance: %AppData%\mediaplayer.exe) and create a Windows service pointing to it as well as a shortcut in the startup folder that is also used to immediately launch QueenOfHearts. This shortcut is the one that contains references to a “david” user highlighted by the DHS CISA report.

Names

Name
JackOfHearts
SLOTHFULMEDIA

Category

Malware

Type

  • Dropper

Information

Mitre Attack

Other Information

Uuid

344874b3-ab32-46b1-826d-13a9ca6b5441

Last Card Change

2022-12-30