Netskope Threat Labs

Jenxcus

ATP Sandbox Adv. HeuristicsAV

Jenxcus (a.k.a. Houdini and Dunihi) is a VBScript based remote access trojan that has targeted users across the Middle East and Asia since 2012. It gives operators command execution, file management, and keylogging on infected machines, and it spreads through phishing messages, malicious documents, and infected removable drives.

First seen
April 2022
Last seen
October 2026
Alert Name
Document-HTML.Worm.Jenxcus
Script-JS.Worm.Jenxcus
Script-WScript.Worm.Jenxcus
Script.Worm.Jenxcus
Shortcut.Worm.Jenxcus
VB:Trojan.Emeka.Jenxcus.699
VB:Trojan.Emeka.Jenxcus.986
VB:Trojan.VBS.Jenxcus.P
Win32.Worm.Jenxcus