ATT&CKSoftwareJSS Loader

JSS Loader

S0648

Malware.View on attack.mitre.org

About this malware

JSS Loader is Remote Access Trojan (RAT) with .NET and C++ variants that has been used by FIN7 since at least 2020.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1053.005
Scheduled Task

JSS Loader has the ability to launch scheduled tasks to establish persistence.

T1059.001
PowerShell

JSS Loader has the ability to download and execute PowerShell scripts.

T1059.005
Visual Basic

JSS Loader can download and execute VBScript files.

T1059.007
JavaScript

JSS Loader can download and execute JavaScript files.

T1105
Ingress Tool Transfer

JSS Loader has the ability to download malicious executables to a compromised host.

T1204.002
Malicious File

JSS Loader has been executed through malicious attachments contained in spearphishing emails.

T1566.001
Spearphishing Attachment

JSS Loader has been delivered by phishing emails containing malicious Microsoft Excel attachments.

Groups that use it1

Campaigns0

None recorded.

References2

  1. CrowdStrike Carbon Spider August 2021 Open source
    Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021.
  2. eSentire FIN7 July 2021 Open source
    eSentire. (2021, July 21). Notorious Cybercrime Gang, FIN7, Lands Malware in Law Firm Using Fake Legal Complaint Against Jack Daniels’ Owner, Brown-Forman Inc.. Retrieved September 20, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.