Tuesday , January 7 2025
Rat

BANKING, MALWARE, FINANCIAL SERVICES, RAT, JS
JSOUTPROX ATTACK FINANCIAL INSTITUTIONS IN APAC

A new version of JSOutProx has been detected by Resecurity. This version is targeting financial services and organizations in the APAC and MENA regions. JSOutProx is a sophisticated attack framework that uses both JavaScript and .NET to carry out its attacks.

The malware allows for the loading of various plugins that carry out additional malicious activities once executed. This malware was first identified in 2019 and was linked to SOLAR SPIDER’s phishing campaigns, distributing the JSOutProx RAT to financial institutions in Africa, the Middle East, South Asia, and Southeast Asia.

            Source: Resecurity

On February 8, 2024, a system integration company based in Saudi Arabia reported an incident where customers of a major bank in the region were targeted. Resecurity helped victims by obtaining the malicious code and recovering the payload. On April 2, 2024, there was another attack, where banking customers were tricked with fake notifications and malicious code.

The new version of JSOutProx, along with the use of platforms like GitHub and GitLab, shows that malicious actors are working hard and smart. JSOutProx has been a threat for five years and continues to evolve, especially for financial institutions’ customers. This year, the threat has expanded to the MENA region, increasing their cybercriminal activity. Resecurity is committed to tracking JSOutProx and protecting financial institutions and their customers worldwide from these harmful activities. To read out the full report click here.

Check Also

2024

Look back; The Worst Hacks of 2024

In 2024, digital security experienced major breaches as cybercriminals and state-backed groups exploited vulnerabilities for …

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending Threat Actor: RomCom group , Scattered Spider, RedGolf, BlueBrave, North Korean Hackers, NoName057 (16), LockBit, Blackcat, ...
Trending Malware: REMCOS Rat, Play Ransomware, LummaC2, HijackLoader, BugSleep, SocGholish, CobaltSrike, Qakbot, Icedid, Trickbot, Xmrig
Trending vulnerability: CVE-2024-43222, CVE-2024-53990, CVE-2024-11609, CVE-2024-11610, CVE-2024-11611, CVE-2023-45727, CVE-2024-11680, ...
Techniques: T1082 ! T1140 ! T1083 ! 1486 ! T1105
Tactics: TA505 ! TA0011 ! TA453 ! TA0002 ! TA0005
06:40