Investigating the New Jellyfish Loader
ID: cb76434a-feb1-580b-8999-50677cc2eeb4
STIX ID: report--cb76434a-feb1-580b-8999-50677cc2eeb4
Feed Name: Cyble Blog
CRIL identified a new .NET-based shellcode loader dubbed "Jellyfish Loader" delivered via a malicious .lnk that triggers mshta to execute obfuscated JavaScript which downloads a lure PDF and the BinSvc.exe loader; the loader collects system information, base64-encodes it, validates/pins SSL certificates, communicates via HTTPS to ping.connectivity-check.com, and contains routines to receive and execute shellcode. The report includes technical analysis, file hashes, a YARA rule, domain/PDNS analysis linking the C2 domain to prior malicious PowerShell activity, and mitigation recommendations, while noting attribution remains unconfirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
