Researchers reported sustained JsOutProx malware operations targeting financial institutions, government bodies, and related customers across India, wider Asia, and the MENA region. The activity relied on spearphishing emails impersonating trusted organizations such as SWIFT, MoneyGram, central banks, and Indian financial agencies, with lures tied to compliance, anti-money laundering, COVID-19 notices, and sector-specific programs such as the Kisan Credit Card scheme. Victims were sent ZIP archives posing as PDFs, images, or office files that contained malicious HTA, JavaScript, or Java payloads, including incidents affecting Indian banks and a later campaign impacting customers of a major Saudi bank.
The malware family used heavily obfuscated, multi-stage loaders executed through mshta or script hosts, then established persistence and contacted Dynamic DNS command-and-control infrastructure. Multiple reports describe a modular toolset capable of command execution, file theft and management, screenshot capture, clipboard and Outlook data theft, proxy and DNS manipulation, privilege escalation, and in newer variants, in-memory execution of .NET assemblies; some samples also used cookie-based HTTP communications carrying encoded victim profiling data. Researchers linked the activity to long-running campaigns against Indian co-operative banks and finance companies, observed infrastructure shifts from GitHub to GitLab for payload hosting, and noted overlaps with other malware operations while attribution remained cautious.

Get the infrastructure and lures behind it.
12 events from the most recent confirmed update back to the earliest known activity.
On March 27, 2024, Resecurity identified a new malware sample from the same group that switched the infection chain from GitHub-hosted payloads to GitLab-hosted payloads.
Around March 25, 2024, the actor behind the campaign registered multiple GitLab accounts and used repositories such as dox05 and docs909 to host malicious payloads.
Around February 8, 2024, Resecurity identified a spike in activity tied to a campaign targeting customers of a major regional bank in Saudi Arabia, as reported by a major system integrator.
Independent cybersecurity researchers had reported some payloads associated with the later APAC and MENA JSOutProx activity as early as November 14, 2023.
Quick Heal said it had been observing JSOutProx attacks against Indian co-operative banks and finance companies since early 2021.
Zscaler reported a JsOutProx campaign in May 2020 targeting governmental and financial institutions in India.
Quick Heal observed a renewed Adwind Java RAT campaign in April 2020 using COVID-19- and banking-themed spearphishing emails against co-operative banks in India.
In April 2020, attackers targeted NABARD, the Reserve Bank of India, IDBI Bank, and Agriculture Insurance Company of India with phishing emails carrying archive attachments containing JsOutProx-linked HTA payloads or a Java backdoor.
Seqrite reported the command-and-control domain used in a renewed Adwind Java RAT campaign against Indian co-operative banks was active from 05-Apr-2020 to 20-Apr-2020.
Quick Heal reported monitoring a JSOutProx campaign targeting Indian co-operative banks and finance companies since at least December 2019.
JsOutProx was first discovered in December 2019, marking the earliest known identification of the malware family later used in multiple phishing campaigns.
FortiGuard Labs discovered a spearphishing campaign targeting governmental, monetary, and financial-sector organizations in Asia using central-bank-themed lures to deliver JsOutProx.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 129 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
7 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourceresecurity.com
Open sourcezscaler.com
Open sourceblogs.quickheal.com
Open sourcefortinet.com
Open sourceseqrite.com
Open sourceseqrite.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.