JSS Loader is a Windows malware family associated primarily with FIN7, also tracked in some reporting under the broader CARBON SPIDER cluster. It has been used as a staged payload and backdoor-capable loader in financially motivated intrusion campaigns targeting sectors including hospitality, restaurants, gambling, and financial organizations. The malware has been observed in both .NET and later C++ implementations, with the C++ rewrite appearing in 2021 distribution activity.
JSS Loader is commonly delivered through spearphishing campaigns using malicious Microsoft Office attachments, including Word and Excel documents, and has also been distributed via VBScript-based infection chains. Once executed, it can establish persistence through scheduled tasks. Its functionality includes downloading and executing additional payloads and scripts, notably PowerShell, VBScript, and JavaScript, making it a flexible staging component for follow-on compromise.
Beyond payload delivery, JSS Loader supports command-and-control communications and collection of host data for operator tasking. Reported capabilities include gathering system and process information via WMI, enumerating files on the desktop, executing native Windows command-line utilities to collect environment details, capturing screenshots in memory for exfiltration, and parsing browser history data from Chromium- and Firefox-family SQLite stores. These behaviors indicate use for reconnaissance and post-compromise situational awareness in addition to malware delivery.
JSS Loader has been used alongside other FIN7 tooling, including Remcos and Harpy, and reflects the group’s long-running tradecraft of phishing-led initial access followed by modular staging, host profiling, and deployment of additional malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
FIN7 is well known to use a spear-phishing campaign to compromise a machine by downloading or executing an obfuscated javascript as the first stage.
has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... has required user execution of a malicious MSI installer... has been executed through user installation of an executable disguised as a flash installer.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
It checks if the host has an enabled UAC by querying the “EnableLua” Registry and saves the output as part of its data gathering.
Like the obfuscated JScript it is also capable of collecting data by using WMI query in “Win32_ComputerSystem”, “Win32_Product” and “Win32_Process”.
This JS is capable of gathering information to the compromised host by executing several WMI query commands.
Additionally, both variants have a function that will list all the files on the desktop of the compromised host that will also send to its C2 server.
It also has some functions that parse the browser information like history and URL visits of users in both Chrome and Firefox applications.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader distributed via malicious Office documents and VBS; an updated C++ rewrite introduced a new packer and shared lure content with Harpy delivery.
Can download and execute VBScript files.
Loader capable of downloading and executing PowerShell scripts.
A FIN7-associated loader/backdoor with .NET and C++ variants that communicates with C2 servers, collects host data via WMI and command-line tools, lists desktop files, captures screenshots in memory, and parses Chrome and Firefox browser databases for history/URL data before exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.