logo

Visa warns of new JSOutProx malware variant targeting financial orgs

ID: 20341d01-ad9a-5651-97d1-2b675d761aa6

STIX ID: report--20341d01-ad9a-5651-97d1-2b675d761aa6

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-04-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Visa and Resecurity warn of a phishing campaign (first seen March 27, 2024) distributing a new version of the JsOutProx JavaScript RAT to banking customers and financial institutions in APAC, MENA, and Africa; the malware is highly obfuscated, delivered via ZIP-attached .js files that fetch payloads from GitLab, and includes modules for remote command execution, persistence, credential/OTP theft, Outlook data harvesting, proxy/DNS manipulation, and additional plugins—IoCs and mitigations are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.