New Malware Used by Solar Spider to Target Saudi Arabian Banks

Published:

spot_img

Sophisticated Threat Group Releases New Version of JSOutProx Malware targeting Middle East Organizations

A notorious threat group known as Solar Spider has unleashed a new and highly sophisticated version of the JSOutProx malware, targeting organizations in the Middle East, particularly in Saudi Arabia. Cybersecurity experts from Resecurity have identified the latest iteration of the malicious JavaScript remote access Trojan (RAT) as a highly adaptable and well-structured program designed to infiltrate and compromise specific environments with ease.

According to Resecurity CEO Gene Yoo, the new JSOutProx variant operates as a multi-stage malware implant with various plug-ins that enable the attackers to tailor their attacks according to the victim’s infrastructure. The threat group has been traced back to China based on its previous targets in regions like India, the Asia-Pacific, Africa, and the Middle East.

Visa has previously documented campaigns utilizing the JSOutProx attack tool, highlighting its ability to evade detection by security systems and extract sensitive financial information from targeted institutions. The malware typically disguises itself as a PDF file within a zip archive and executes JavaScript once opened, initiating a two-stage attack that can lead to the theft of crucial data.

As Solar Spider continues to target high-profile organizations, Visa urges companies to educate their employees on identifying and handling suspicious emails to prevent malware infections. By implementing robust defense-in-depth strategies, such as regular patching, network segmentation, and vulnerability management, businesses can mitigate the risk posed by sophisticated threat groups like Solar Spider and protect their valuable data from falling into the wrong hands.

spot_img

Related articles

Recent articles

Microsoft patches record 622 vulnerabilities, including two actively exploited zero-days

Microsoft has issued a significant security update, addressing a record 622 vulnerabilities in its products, including two actively exploited zero-day vulnerabilities. This update, part...

Romania’s Land Registry Agency Works to Restore Services Following Cyberattack Disruption

A cyberattack has disrupted Romania's digital land registry systems, as reported by the National Agency for Cadastre and Land Registration (ANCPI). The agency confirmed...

CVE-2026-56164 and CVE-2026-56155 in Microsoft SharePoint and Active Directory Patches Released Amid Active Exploitation Concerns

On July 20, 2026, Microsoft released critical patches addressing two vulnerabilities, CVE-2026-56164 and CVE-2026-56155, affecting SharePoint Server and Active Directory Federation Services, respectively. These...

Abbott Laboratories Investigates Dual Cybersecurity Breaches Linked to ShinyHunters and ShadowByt3$

Abbott Laboratories is currently investigating two significant cybersecurity incidents affecting its Cancer Diagnostics and Core Laboratory diagnostics businesses. The first incident involves unauthorized access...