New Jellyfish Loader Threat Discovered: Advanced Techniques for System Infiltration
ID: e52f5a6e-850b-51c9-bfff-45420cb260b9
STIX ID: report--e52f5a6e-850b-51c9-bfff-45420cb260b9
Feed Name: The Cyber Express
Cyble Research and Intelligence Labs (CRIL) discovered and analyzed Jellyfish Loader, a 64-bit .NET shellcode loader distributed via a malicious .lnk inside a ZIP archive; the loader collects system information (encoded as Base64 JSON), communicates with a C2 at https://ping.connectivity-check.com using HTTPS POST, embeds dependencies via Fody/Costura for stealth, and can download/execute additional payloads (SHA-256: e654e97efb6214bea46874a49e173a3f8b40ef30fd0179b1797d14bcc2c2aa6c). The report notes similarities to Olympic Destroyer/Hades techniques, lists indicators and mitigations (AV/whitelisting/segmentation/SSL inspection), and provides contextual infrastructure details for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
