JSOutProx

First seen
2022-06-15 00:00:00
Malware type
loader, spyware
Family
Malware family
Profile updated
2026-07-07 12:58:05

Targeted industries: technology-and-telecommunications financial-services

Context

JSOutProx is a sophisticated attack framework built using both Javascript and .NET. It uses the .NET (de)serialization feature to interact with a Javascript file which is the core module running on a victim machine. Once the malware is run on the victim, the framework can load several plugins performing additional malicious activities on the target.

Reports & references

  • CrowdStrike — Report2021Gtr (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Jsoutprox (report)
  • resecurity.com — The New Version Of Jsoutprox Is Attacking Financial Institutions In Apac And Mena Via Gitlab Abuse (report)
  • twitter.com — 1208022180241530882 (report)
  • fortinet.com — Adversary Playbook Javascript Rat Looking For That Government Cheese (report)
  • blog.yoroi.company — Unveiling Jsoutprox A New Enterprise Grade Implant (report)
  • blogs.quickheal.com — Multi Staged Jsoutprox Rat Targets Indian Cooperative Banks And Finance Companies (report)
  • seqrite.com — Whitepaper Multi Staged Jsoutprox Rat Target Indian Co Operative Banks And Finance Companies (report)
  • yoroi.company — Financial Institutions In The Sight Of New Jsoutprox Attack Waves (report)
  • zscaler.com — Targeted Attacks Indian Government And Financial Institutions Using Jsoutprox Rat (report)

External references