New Wave of JSOutProx Malware Targeting Financial Firms in APAC and MENA
ID: 6e9c1cc8-f90b-5d6a-bec7-d7cf61f9bfcb
STIX ID: report--6e9c1cc8-f90b-5d6a-bec7-d7cf61f9bfcb
Feed Name: The Hacker News
Resecurity documents a renewed wave of JSOutProx attacks targeting financial organizations in APAC and MENA: JSOutProx is a JavaScript/.NET RAT delivered via spear-phishing (malicious .js, HTA, or obfuscated attachments) that loads plugins to exfiltrate payment data, harvest credentials (Outlook, Symantec VIP OTPs), capture clipboard content, and manipulate proxy settings; it uses the HTTP Cookie header for C2, has been active since 2019 with a spike beginning 8 February 2024, and artifacts were briefly hosted on GitHub/GitLab. The activity is attributed historically to the Solar Spider actors and may be linked to China-affiliated groups, posing a significant fraud and financial risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
