Tag: JSOutProx malware

New Wave of JSOutProx Malware Targeting Financial Firms in APAC and MENA
News

New Wave of JSOutProx Malware Targeting Financial Firms in APAC and MENA

The Middle East and North Africa (MENA) and Asia-Pacific (APAC) financial institutions are the target of JSOutProx, a new "evolving threat" variant. In a technical paper released this week, Resecurity stated that "JSOutProx is an advanced attack framework that leverages both JavaScript and.NET." It interacts with a core JavaScript module that is operating on the victim's computer by using the.NET (de)serialization functionality. Once it's run, the malware allows the framework to load further plugins, which in turn carry out more harmful operations on the target. Early attacks dispersing JSOutProx were first discovered by Yoroi in December 2019 and have been linked to a threat actor known as Solar Spider. The history of bank strikes and other large company actions in Europe and As...
Visa warns of new JSOutProx malware variant targeting financial orgs
News

Visa warns of new JSOutProx malware variant targeting financial orgs

Visa is alerting users to an increase in JsOutProx malware detections, which is aimed at financial institutions and their clients. Visa's Payment Fraud Disruption (PDF) team sent a security alert to card issuers, processors, and acquirers on March 27, 2024, which BleepingComputer was able to view. According to the alert, Visa learned about a new phishing operation that was disseminating the remote access trojan on that day. Financial institutions throughout Africa, the Middle East, and South and Southeast Asia were the target audience for this campaign. JsOutProx is a highly obfuscated JavaScript backdoor and remote access trojan (RAT) that was first discovered in December 2019. Its operators can run shell commands, download more payloads, execute files, take screenshots, establi...