Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 21:48:59 UTC Home > List all groups > List all tools > List all groups using tool JackOfHearts Tool: JackOfHearts Names JackOfHearts SLOTHFULMEDIA Category Malware Type Dropper Description (Kaspersky) JackOfHearts is the dropper associated with QueenOfHearts: its role is to write the malware somewhere on the disk (for instance: %AppData%\mediaplayer.exe) and create a Windows service pointing to it as well as a shortcut in the startup folder that is also used to immediately launch QueenOfHearts. This shortcut is the one that contains references to a “david” user highlighted by the DHS CISA report. Information MITRE ATT&CK Last change to this tool card: 30 December 2022 Download this tool card in JSON format All groups using tool JackOfHearts Changed Name Country Observed APT groups IAmTheKing 2018 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=344874b3-ab32-46b1-826d-13a9ca6b5441 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=344874b3-ab32-46b1-826d-13a9ca6b5441 Page 1 of 1