JSS Loader
MITRE ATT&CK: S0648 View on attack.mitre.org
Aliases: JSS Loader
- First seen
- 2020-01-01 00:00:00
- Malware type
- rat, loader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 29 (10 malicious)
- Last IoC activity
- 2026-09-01 20:38:54
- Profile updated
- 2026-07-07 13:21:57
Targeted industries: financial-services retail-and-hospitality
Context
JSS Loader is Remote Access Trojan (RAT) with .NET and C++ variants that has been used by FIN7 since at least 2020.
Recent IoC activity
10 malicious indicators in Maltiverse are attributed to JSS Loader (S0648). The 10 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | its-zach-time.com | 2026-09-03 | 1 |
| hostname | bluelotuslasvegas.org | 2026-09-02 | 1 |
| hostname | twopawandcompany.net | 2026-09-02 | 1 |
| hostname | divorceradio.com | 2026-09-02 | 2 |
| IP address | 209.141.57.163 | 2026-08-28 | 5 |
| IP address | 209.141.60.216 | 2026-08-17 | 3 |
| IP address | 209.141.52.48 | 2026-08-04 | 12 |
| hostname | meditatesrilanka.com | 2026-04-30 | 1 |
| hostname | modolorem.com | 2026-02-18 | 1 |
| file sample | Quickbooks-11646-June-2022 (3).wsf | 2025-02-15 | 1 |
Detection coverage
- 371 Sigma rules
Malware & tools used
- Scheduled Task (attack-pattern)
- Visual Basic (attack-pattern)
- JavaScript (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Malicious File (attack-pattern)
- PowerShell (attack-pattern)
Used by threat actors
- FIN7 (threat-actor)
Reports & references
- CrowdStrike — Carbon Spider Embraces Big Game Hunting Part 1 (report)
- MITRE ATT&CK — S0648 (report)
- esentire.com — Notorious Cybercrime Gang Fin7 Lands Malware In Law Firm Using Fake Legal Complaint Against Jack Daniels Owner Brown Forman Inc (report)