logo

Solar Spider Spins Up New Malware to Entrap Saudi Arabian Financial Firms

ID: e165bc49-7a0f-5155-9fad-5f14630489f8

STIX ID: report--e165bc49-7a0f-5155-9fad-5f14630489f8

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-04-08

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

JSOutProx, a highly obfuscated JavaScript remote access Trojan used by the Solar Spider group, has a new modular version targeting financial organizations and some governments across APAC and MENA (including Saudi Arabia). The malware is delivered as JavaScript disguised in PDFs within ZIP archives and pulls plugin modules from repositories (GitHub/GitLab) to exfiltrate payment data and credentials, enable remote control, and manipulate victim environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.