Solar Spider is a financially motivated cybercrime threat actor associated with phishing-led malware campaigns delivering the JSOutProx remote access framework. Activity linked to this actor has been observed since at least 2019, initially targeting financial institutions across Africa, the Middle East, South Asia, and Southeast Asia, and later expanding toward Latin America. Reported victimology also includes government organizations in India and Taiwan and financial organizations in the Philippines, Laos, Singapore, Malaysia, India, and Saudi Arabia. Solar Spider commonly uses social-engineering lures themed around financial transactions and money transfers, including spoofed payment notifications, to obtain initial access. Its operations have relied on obfuscated JavaScript payloads and staged delivery infrastructure hosted on public code repositories. JSOutProx is a modular JavaScript and .NET malware framework that supports remote command execution, file operations, environment profiling, proxy deployment, persistence, clipboard theft, Outlook data access, token theft, DNS and hosts-file manipulation, and privilege-escalation functionality. Observed tradecraft includes masquerading, use of Windows scripting components, victim reconnaissance, post-compromise plugin deployment, and defense-evasion through obfuscation and rapidly rotated hosting infrastructure. The actor has been tied to campaigns against banking customers and institutions, and law-enforcement reporting has linked suspected members to bank fraud activity. Some reporting has assessed with only moderate confidence that JSOutProx developers may be China-based or China-affiliated, while separate reporting noted arrests of suspected Nigerian members. The available information does not establish a single origin country for Solar Spider at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
41 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Criminal group whose alleged members were arrested in India for planning to exploit vulnerabilities in cooperative banks and transfer stolen funds to mule accounts; they had already stolen funds from a bank in Gujarat.
Conducting phishing-led JSOutProx RAT campaigns against financial institutions and government-related targets across APAC, MENA, Africa, and South/Southeast Asia, using multi-stage JavaScript/.NET implants hosted on GitHub and GitLab.
Financially motivated threat group that began shifting attention to Latin America in 2024 (Russia mentioned for Renaissance Spider; Solar Spider geography not explicitly stated).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.