Visa warns of new JSOutProx malware variant targeting financial orgs
ID: 20341d01-ad9a-5651-97d1-2b675d761aa6
STIX ID: report--20341d01-ad9a-5651-97d1-2b675d761aa6
Feed Name: Bleeping Computer
Visa and Resecurity warn of a phishing campaign (first seen March 27, 2024) distributing a new version of the JsOutProx JavaScript RAT to banking customers and financial institutions in APAC, MENA, and Africa; the malware is highly obfuscated, delivered via ZIP-attached .js files that fetch payloads from GitLab, and includes modules for remote command execution, persistence, credential/OTP theft, Outlook data harvesting, proxy/DNS manipulation, and additional plugins—IoCs and mitigations are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
