JSSLoader
- First seen
- 2019-03-01 00:00:00
- Malware type
- loader
- Family
- Malware family
- Last IoC activity
- 2026-07-21 08:34:13
- Profile updated
- 2026-07-07 13:02:25
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical
Context
JSSLoader is a loader-type malware primarily used to distribute additional malicious payloads. It often arrives via malspam campaigns, particularly targeting sensitive industries like financial services and healthcare. The malware is capable of executing additional code downloaded from attacker-controlled servers.
Detection coverage
- 3 YARA rules
Used by threat actors
- Storm-0324 (threat-actor)
Detection rules
- ARKBIRD_SOLG_MAL_Jssloader_Jun_2021_1 (yara-rule)
- DITEKSHEN_MALWARE_Win_Jssloader (yara-rule)
- MALPEDIA_Win_Jssloader_Auto (yara-rule)
Reports & references
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- Microsoft — Malware Distributor Storm 0324 Facilitates Ransomware Access (report)
- proofpoint.com — Jssloader Recoded And Reloaded (report)
- CrowdStrike — Carbon Spider Embraces Big Game Hunting Part 1 (report)
- Mandiant — Evolution Of Fin7 (report)
- CrowdStrike — Carbon Spider Embraces Big Game Hunting Part 2 (report)
- blog.morphisec.com — Vmware Identity Manager Attack Backdoor (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Jssloader (report)
- malwarebytes.app.box.com — Ym6R7O5Hq0Rx2Nxjbctfv2Sw5Vx386Ni (report)
- splunk.com — Fin7 Tools Resurface In The Field Splinter Or Copycat (report)
- blog.morphisec.com — New Jssloader Trojan Delivered Through Xll Files (report)
- secureworks.com — Excel Add Ins Deliver Jssloader Malware (report)
- malwarebytes.com — Jssloader The Shellcode Edition (report)
- morphisec.com — Fin7%20Jssloader%20Final%20Web (report)
- bleepingcomputer.com — Malicious Microsoft Excel Add Ins Used To Deliver Rat Malware (report)