JSOutProx is a multi-stage, heavily obfuscated JavaScript-based remote access trojan active since at least late 2019 and used primarily in targeted campaigns against financial institutions and government organizations in Asia, with later activity also affecting APAC, MENA, Africa, South Asia, and Southeast Asia. It has been associated with phishing operations attributed in public reporting to Solar Spider and has repeatedly targeted Indian banking entities, including co-operative banks and other financial-sector organizations, as well as selected government institutions.
Initial access is commonly achieved through spearphishing emails carrying compressed attachments that contain malicious JavaScript or HTA content, often themed to match the recipient’s business context such as banking, compliance, payment notifications, or government workflows. Campaigns have used spoofed or compromised email accounts and masquerading techniques to make payloads appear as benign document-related files. Some operations also staged payloads on code-hosting platforms as part of the delivery chain.
Once executed through Windows Script Host or mshta, JSOutProx deobfuscates itself at runtime and establishes command-and-control communications over HTTP. It profiles the victim host by collecting system and user information and has been observed encoding victim metadata into HTTP cookies. The malware supports a modular plugin architecture and a broad command set for remote administration, including command execution, script evaluation, file and process operations, implant update and removal, host restart or shutdown, and configurable beacon timing.
Observed plugin functionality includes system reconnaissance, screenshot capture, remote keyboard and mouse interaction, clipboard theft and manipulation, Outlook account and contact harvesting, DNS and proxy configuration changes, and theft of one-time passwords from Symantec VIP. Newer variants added the ability to download and execute .NET assemblies directly in memory, making JSOutProx a hybrid JavaScript and .NET attack framework. Public reporting also describes privilege-escalation and UAC-bypass features, persistence mechanisms, and defense-evasion measures such as extreme obfuscation, hidden execution windows, and techniques intended to improve execution of downloaded payloads.
The malware has been used in financially motivated campaigns, especially against smaller banks and finance companies that may have weaker defensive maturity, though government targeting has also been documented. Reporting has noted similarities between JSOutProx activity and earlier Adwind-related campaigns against Indian institutions, but any deeper attribution linkage remains uncertain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Resecurity has detected a new version of JSOutProx, targeting financial services and organizations in the APAC and MENA regions. JSOutProx is a sophisticated attack framework utilizing both JavaScript and .NET.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Multiple banking customers were targeted via an impersonation attack using the "mike.will@my[.]com" email account. The actors employed a fake SWIFT payment notification (for enterprise customers) and a Moneygram template (for private customers), using misleading notifications to confuse victims and execute malicious code.
One unique feature of the malware is its use of the Cookie header field in its command and control (C2C) communication.
In the result of the multi-stage infection chain, the actors drop multiple JS-based obfuscated payloads to collect sensitive information and plant a proxy server to connect remotely to the victim.
47 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A JavaScript/HTA-based remote access backdoor that communicates with a C2 over HTTP POST using encoded cookie data, gathers host information, supports persistence via Windows Run registry keys, and can execute commands including downloading/executing scripts, restarting, uninstalling, file operations, shell access, screen capture, and execution of server-supplied JavaScript or VBScript.
A JavaScript/HTA-based remote access trojan and backdoor that communicates with a C2 server over HTTP POST using encoded cookie data, gathers host information, supports persistence via registry run keys, and can download/execute scripts, run JavaScript or VBScript, manage files, invoke shell access, capture screens, reboot/shutdown systems, and uninstall/install itself.
A modular JavaScript/.NET remote access trojan and backdoor framework that enables plugin-based post-compromise activity including command execution, file upload/download, persistence, screenshot capture, keyboard and mouse control, clipboard theft/modification, Outlook data access, DNS/hosts file changes, proxy configuration, privilege escalation/UAC bypass, and remote proxying. It uses obfuscated multi-stage JS payloads and communicates with C2 using data encoded in the HTTP Cookie header.
A multi-staged remote access trojan targeting Indian co-operative banks and finance companies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.