logo

Investigating the New Jellyfish Loader

ID: cb76434a-feb1-580b-8999-50677cc2eeb4

STIX ID: report--cb76434a-feb1-580b-8999-50677cc2eeb4

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2024-07-17

Date Updated: 2026-07-20

...
...

CRIL identified a new .NET-based shellcode loader dubbed "Jellyfish Loader" delivered via a malicious .lnk that triggers mshta to execute obfuscated JavaScript which downloads a lure PDF and the BinSvc.exe loader; the loader collects system information, base64-encodes it, validates/pins SSL certificates, communicates via HTTPS to ping.connectivity-check.com, and contains routines to receive and execute shellcode. The report includes technical analysis, file hashes, a YARA rule, domain/PDNS analysis linking the C2 domain to prior malicious PowerShell activity, and mitigation recommendations, while noting attribution remains unconfirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.