JSOutProx
- First seen
- 2022-06-15 00:00:00
- Malware type
- loader, spyware
- Family
- Malware family
- Profile updated
- 2026-07-07 12:58:05
Targeted industries: technology-and-telecommunications financial-services
Context
JSOutProx is a sophisticated attack framework built using both Javascript and .NET. It uses the .NET (de)serialization feature to interact with a Javascript file which is the core module running on a victim machine. Once the malware is run on the victim, the framework can load several plugins performing additional malicious activities on the target.
Reports & references
- CrowdStrike — Report2021Gtr (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Jsoutprox (report)
- resecurity.com — The New Version Of Jsoutprox Is Attacking Financial Institutions In Apac And Mena Via Gitlab Abuse (report)
- twitter.com — 1208022180241530882 (report)
- fortinet.com — Adversary Playbook Javascript Rat Looking For That Government Cheese (report)
- blog.yoroi.company — Unveiling Jsoutprox A New Enterprise Grade Implant (report)
- blogs.quickheal.com — Multi Staged Jsoutprox Rat Targets Indian Cooperative Banks And Finance Companies (report)
- seqrite.com — Whitepaper Multi Staged Jsoutprox Rat Target Indian Co Operative Banks And Finance Companies (report)
- yoroi.company — Financial Institutions In The Sight Of New Jsoutprox Attack Waves (report)
- zscaler.com — Targeted Attacks Indian Government And Financial Institutions Using Jsoutprox Rat (report)