JSSLoader

First seen
2019-03-01 00:00:00
Malware type
loader
Family
Malware family
Last IoC activity
2026-07-21 08:34:13
Profile updated
2026-07-07 13:02:25

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical

Context

JSSLoader is a loader-type malware primarily used to distribute additional malicious payloads. It often arrives via malspam campaigns, particularly targeting sensitive industries like financial services and healthcare. The malware is capable of executing additional code downloaded from attacker-controlled servers.

Detection coverage

  • 3 YARA rules

Used by threat actors

Detection rules

  • ARKBIRD_SOLG_MAL_Jssloader_Jun_2021_1 (yara-rule)
  • DITEKSHEN_MALWARE_Win_Jssloader (yara-rule)
  • MALPEDIA_Win_Jssloader_Auto (yara-rule)

Reports & references

  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • Microsoft — Malware Distributor Storm 0324 Facilitates Ransomware Access (report)
  • proofpoint.com — Jssloader Recoded And Reloaded (report)
  • CrowdStrike — Carbon Spider Embraces Big Game Hunting Part 1 (report)
  • Mandiant — Evolution Of Fin7 (report)
  • CrowdStrike — Carbon Spider Embraces Big Game Hunting Part 2 (report)
  • blog.morphisec.com — Vmware Identity Manager Attack Backdoor (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Jssloader (report)
  • malwarebytes.app.box.com — Ym6R7O5Hq0Rx2Nxjbctfv2Sw5Vx386Ni (report)
  • splunk.com — Fin7 Tools Resurface In The Field Splinter Or Copycat (report)
  • blog.morphisec.com — New Jssloader Trojan Delivered Through Xll Files (report)
  • secureworks.com — Excel Add Ins Deliver Jssloader Malware (report)
  • malwarebytes.com — Jssloader The Shellcode Edition (report)
  • morphisec.com — Fin7%20Jssloader%20Final%20Web (report)
  • bleepingcomputer.com — Malicious Microsoft Excel Add Ins Used To Deliver Rat Malware (report)

External references