FIN7 has continued to evolve its malware delivery and post-compromise tooling, with multiple reports tying the group to campaigns that use malicious Excel add-ins (.xll) to deliver a rewritten JSSLoader. Malwarebytes reported a late-June malspam operation in which an XLL component launched JSSLoader and dropped a secondary .NET payload, while later reporting from Morphisec and Secureworks also linked new JSSLoader activity to Excel add-ins. Researchers said the newer JSSLoader variants expand on earlier versions with added functionality, including enhanced data-exfiltration capabilities.
The activity fits a broader pattern in FIN7 intrusions documented by Mandiant, which showed the group shifting from older loaders such as LOADOUT and GRIFFON toward more flexible access tools including POWERPLANT and Cobalt Strike BEACON, while continually rewriting malware to evade detection. Mandiant also described FIN7 using compromised RDP credentials, shellcode loaders, reconnaissance, Kerberoasting, and customized backdoors, underscoring that the latest JSSLoader delivery chain is part of a longer-running effort by the financially motivated group to refine initial access, persistence, and follow-on intrusion capability.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
In its analysis of the late-June campaign, Malwarebytes determined that FIN7 was using another rewrite of JSSLoader with expanded capabilities. The newly observed version included data exfiltration functions, and one analyzed sample dropped a secondary .NET payload during execution.
Malwarebytes observed a malspam campaign in late June and attributed it to FIN7. The attack chain used an XLL component as an initial step leading to JSSLoader.
Mandiant published research describing FIN7’s evolution from 2020 through 2021, including its move away from LOADOUT and GRIFFON toward POWERPLANT and BEACON. The report also highlighted distinctive PowerShell execution patterns and a 2021 intrusion case involving TERMITE and victim-customized POWERPLANT.
Morphisec Labs reported a new JSSLoader campaign linked to FIN7 that used phishing emails with malicious Excel XLL or XLM add-ins to download and execute the payload. The updated malware added stronger obfuscation, including renamed functions and runtime string concatenation, to hinder static and endpoint detection.
Mandiant identified an uptick in FIN7-suspected activity during 2021 across five intrusions beginning in April 2021. In these intrusions, FIN7 shifted away from earlier loaders toward direct deployment of POWERPLANT and Cobalt Strike BEACON.
Mandiant reported that FIN7 was first observed using the POWERPLANT PowerShell backdoor in late summer 2020. It was initially delivered after successful GRIFFON infections, with August 2020 specifically noted for this delivery pattern.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
secureworks.com
Open sourceblog.morphisec.com
Open sourcemalwarebytes.com
Open sourcemandiant.com
Open sourcebleepingcomputer.com
Open sourcemorphisec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.