Description
AdWind is a remote access trojan written in Java that runs on Windows, macOS, Linux, and Android, which makes it one of the most widely ported RAT families. It can log keystrokes, capture screenshots, browse and transfer files, and download and run additional payloads on infected devices. Criminal groups sell it on underground forums, and its long history of active development has produced many rebranded variants that continue to circulate.
Stats
- First seen
- February 2022
- Last seen
- October 2026
Also known as
AdwindJrat
Alert name variants
| Alert Name |
|---|
| Archive-JAR.Backdoor.Adwind |
| Archive-JAR.Trojan.AdWind |
| Binary.Backdoor.Adwind |
| Binary.Trojan.AdWind |
| ByteCode-JAVA.Backdoor.Adwind |
| ByteCode-JAVA.Exploit.Adwind |
| ByteCode-JAVA.Trojan.AdWind |
| Document-HTML.Downloader.Adwind |
| Email-MSG.Trojan.AdWind |
| Email.Backdoor.Adwind |



