Ostap is a Windows-focused JavaScript malware loader and downloader used in criminal email campaigns to deliver additional payloads, most notably TrickBot and other malware families associated with follow-on intrusion activity. It is characterized by heavy obfuscation, including large volumes of junk code and repeated String.fromCharCode-based decoding logic intended to frustrate static analysis and evade automated sandboxing. Some observed variants hide their script content inside malicious Office documents, including in visually concealed text, and reconstruct or launch the JavaScript through macro-driven execution chains.
Ostap has been distributed through phishing campaigns using macro-enabled Microsoft Office documents and topical social-engineering lures, including invoice themes and COVID-19-related messaging. In documented campaigns, enabling document macros triggered execution chains that dropped or built the Ostap JavaScript downloader, which then retrieved second-stage malware. Researchers and defenders have repeatedly linked Ostap activity to delivery of TrickBot, including campaigns targeting organizations in sectors such as healthcare, manufacturing, and pharmaceuticals. Threat reporting also associates Ostap usage with cybercrime delivery ecosystems tracked under actors such as TA800.
The malware’s primary role is payload retrieval and execution rather than long-term resident access. It has been observed as a first-stage component in multi-step infections that can ultimately support broader post-compromise operations, including ransomware enablement through downstream malware. Ostap has also appeared in SSL/TLS malware telemetry, indicating use of encrypted command-and-control or payload delivery infrastructure. Available reporting supports classifying Ostap as a JavaScript-based loader/downloader used in Windows-centric malspam operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This threat actor attempts to deliver and install banking malware or malware loaders including The Trick, BazaLoader, Buer Loader, and Ostap.
"The group also uses Ostap, a malware downloader that uses JavaScript to hide itself from security sandbox analysis tools."
11 distinct techniques documented for this family, organized by ATT&CK tactic.
As soon as OSTAP is created in the form of a BAT file, this file is executed
They contained Microsoft Word attachments that use Microsoft Office macros to download the next stage payload.
During a recent investigation dealing with ransomware attack, CERT Intrinsec faced OSTAP loader... Figure 1 : Extract of the loader code (Javascript)
The Server field is empty in the script, which will later cause an error that the attackers will actually abuse to properly execute their own code.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
JavaScript downloader delivered through malicious Office documents and macros; it is written to a BAT file and executed to continue the infection chain.
A malware loader delivered by TA800 as part of initial access activity.
Downloader used to fetch/execute additional payloads; noted for JavaScript-based evasion against sandbox analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.