logo

New Jellyfish Loader Threat Discovered: Advanced Techniques for System Infiltration

ID: e52f5a6e-850b-51c9-bfff-45420cb260b9

STIX ID: report--e52f5a6e-850b-51c9-bfff-45420cb260b9

Feed Name: The Cyber Express

Threat Score
65/100

Date Published: 2024-07-16

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

Cyble Research and Intelligence Labs (CRIL) discovered and analyzed Jellyfish Loader, a 64-bit .NET shellcode loader distributed via a malicious .lnk inside a ZIP archive; the loader collects system information (encoded as Base64 JSON), communicates with a C2 at https://ping.connectivity-check.com using HTTPS POST, embeds dependencies via Fody/Costura for stealth, and can download/execute additional payloads (SHA-256: e654e97efb6214bea46874a49e173a3f8b40ef30fd0179b1797d14bcc2c2aa6c). The report notes similarities to Olympic Destroyer/Hades techniques, lists indicators and mitigations (AV/whitelisting/segmentation/SSL inspection), and provides contextual infrastructure details for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.