Financial Institutions in APAC and MENA Facing New Wave of JSOutProx Malware

Published:

spot_img

Financial organizations in the Asia-Pacific (APAC) and Middle East and North Africa (MENA) are under siege by a new cybersecurity threat known as JSOutProx. Resecurity, in a recent technical report, described JSOutProx as a sophisticated attack framework that combines JavaScript and .NET to carry out malicious activities on victims’ machines.

Initially discovered in December 2019 by Yoroi, JSOutProx has been linked to Solar Spider, a threat actor with a history of targeting banks and major companies in Asia and Europe. Recent attacks have focused on small finance banks in India and government establishments, using spear-phishing emails with malicious JavaScript attachments.

The malware, which acts as a remote access trojan (RAT), can exfiltrate data, manipulate files, control proxy settings, and access sensitive information like Microsoft Outlook account details and Symantec VIP passwords. A unique aspect of JSOutProx is its use of the Cookie header field for command-and-control communications.

Resecurity reported a surge in JSOutProx attacks starting February 8, 2024, with cyber criminals distributing fake payment notifications to trick recipients into executing the malicious code. The attackers have been hosting the malware on GitHub and GitLab repositories before taking them down and creating new ones to avoid detection.

While the exact origins of the e-crime group behind JSOutProx remain unknown, Resecurity believes they may have connections to China. This development coincides with the emergence of GEOBOX, a new tool on the dark web that repurposes Raspberry Pi devices for fraudulent activities.

The cybersecurity community is concerned about the widespread adoption of GEOBOX, as it could enable various threat actors to engage in state-sponsored attacks, financial fraud, and other illegal activities. The evolution of cyber threats like JSOutProx and tools like GEOBOX underscores the importance of robust cybersecurity measures for organizations in the financial sector.

spot_img

Related articles

Recent articles

U.S. Secures Five Guilty Pleas and $15M Seized in Major Cybercrime Case

Disrupting Illicit Financing: The Justice Department's Action Against North Korean Operations The U.S. Department of Justice (DOJ) has recently made significant strides in combating illicit...

DBS and UnionPay Launch SplendorPlus Campaign to Enhance Consumer Benefits and Strengthen China-Singapore Financial Ties

Enhanced Cross-Border Payment Solutions Between China and Singapore The Growing Financial Synergy As China and Singapore strengthen their financial cooperation, particularly through initiatives like the Belt...

Dubai Airshow 2025: The Biggest Yet, Showcasing eVTOL Innovations, a Mega Space Pavilion, and 1,500 Exhibitors

Dubai Airshow 2025: The Biggest Innovation Showcase Yet Overview of Dubai Airshow 2025 The Dubai Airshow 2025 is gearing up to take place at Dubai World...

Threat of ‘Digital Arrest’ in Mumbai: 142 Cases, ₹114 Crore Lost — Police Launch Senior Citizen Protection Drive

Understanding the Rise of Cybercrime in Mumbai: The Alarming Case of "Digital Arrest" Cybercrime patterns in Mumbai have seen a remarkable transformation in recent years....