JSS Loader

MITRE ATT&CK: S0648 View on attack.mitre.org

Aliases: JSS Loader

First seen
2020-01-01 00:00:00
Malware type
rat, loader
Family
Malware family
Operating systems
windows
Related IoCs
29 (10 malicious)
Last IoC activity
2026-09-01 20:38:54
Profile updated
2026-07-07 13:21:57

Targeted industries: financial-services retail-and-hospitality

Context

JSS Loader is Remote Access Trojan (RAT) with .NET and C++ variants that has been used by FIN7 since at least 2020.

Recent IoC activity

10 malicious indicators in Maltiverse are attributed to JSS Loader (S0648). The 10 most recently updated:

TypeIndicatorUpdatedSources
hostname its-zach-time.com 2026-09-03 1
hostname bluelotuslasvegas.org 2026-09-02 1
hostname twopawandcompany.net 2026-09-02 1
hostname divorceradio.com 2026-09-02 2
IP address 209.141.57.163 2026-08-28 5
IP address 209.141.60.216 2026-08-17 3
IP address 209.141.52.48 2026-08-04 12
hostname meditatesrilanka.com 2026-04-30 1
hostname modolorem.com 2026-02-18 1
file sample Quickbooks-11646-June-2022 (3).wsf 2025-02-15 1

Detection coverage

  • 371 Sigma rules

Malware & tools used

  • Scheduled Task (attack-pattern)
  • Visual Basic (attack-pattern)
  • JavaScript (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Malicious File (attack-pattern)
  • PowerShell (attack-pattern)

Used by threat actors

  • FIN7 (threat-actor)

Reports & references

  • CrowdStrike — Carbon Spider Embraces Big Game Hunting Part 1 (report)
  • MITRE ATT&CK — S0648 (report)
  • esentire.com — Notorious Cybercrime Gang Fin7 Lands Malware In Law Firm Using Fake Legal Complaint Against Jack Daniels Owner Brown Forman Inc (report)

External references