Solar Spider Spins Up New Malware to Entrap Saudi Arabian Financial Firms
ID: e165bc49-7a0f-5155-9fad-5f14630489f8
STIX ID: report--e165bc49-7a0f-5155-9fad-5f14630489f8
Feed Name: Dark Reading
Threat Score
JSOutProx, a highly obfuscated JavaScript remote access Trojan used by the Solar Spider group, has a new modular version targeting financial organizations and some governments across APAC and MENA (including Saudi Arabia). The malware is delivered as JavaScript disguised in PDFs within ZIP archives and pulls plugin modules from repositories (GitHub/GitLab) to exfiltrate payment data and credentials, enable remote control, and manipulate victim environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
