JSSLoader is a Windows malware family associated primarily with FIN7, also tracked as ELBRUS, Carbon Spider, Sangria Tempest, and in some reporting linked to distribution by TA543 or Storm-0324 as part of broader cybercrime delivery chains. First observed in 2019, it has been described both as a remote access trojan and as an early-stage loader because it provides interactive post-compromise control while also profiling hosts and retrieving additional payloads for follow-on intrusion activity. JSSLoader has been used to facilitate access that later supports deployment of other tooling, including Cobalt Strike and ransomware operations.
The malware collects basic system information from infected hosts, communicates with command-and-control infrastructure, executes operator commands, downloads and launches additional payloads, and has been reported to support data exfiltration and self-updating. Observed tradecraft also includes persistence through Windows shortcut files, and some variants have been associated with browser data collection activity. JSSLoader samples have used lightweight obfuscation and defense-evasion measures such as renamed classes and functions, split and concatenated strings, simple decoding routines, and alternate implementations across .NET and C++ to hinder static analysis and signature-based detection.
A prominent delivery mechanism has been phishing campaigns using malicious Microsoft Excel add-ins, especially XLL attachments, often themed around invoices or payments. In these campaigns, the add-in executes within the Excel process after user approval, downloads the JSSLoader payload, and launches it as a new process. Other observed delivery chains tied to JSSLoader distribution have included malspam, landing pages, traffic distribution systems, SharePoint-hosted scripts, and intermediate script-based downloaders. Reporting also links JSSLoader distribution to opportunistic large-scale email campaigns targeting organizations across sectors including finance, manufacturing, technology, retail, healthcare, education, transportation, hospitality, and restaurants.
JSSLoader has undergone multiple rewrites over time, including a temporary shift from .NET to C++ in 2021 before later .NET variants reappeared. Across versions, its core role has remained consistent: establish foothold access, profile the victim environment, maintain persistence, and enable delivery of subsequent malware or hands-on-keyboard intrusion activity. Its long-running association with FIN7 and adjacent cybercrime distribution ecosystems makes it a notable component in financially motivated intrusion chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Storm-0324 has used a variety of files to host the JavaScript code, including WSF and Ekipa publisher files exploiting the CVE-2023-21715 local security feature bypass vulnerability. | The actor is known to distribute the JSSLoader malware, which facilitates access for the ransomware-as-a-service (RaaS) actor Sangria Tempest.
ELBRUS is responsible for developing and distributing multiple custom malware families used for persistence, including JSSLoader and Griffon.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Secureworks® Counter Threat Unit™ (CTU) researchers observed multiple malicious Microsoft Excel add-ins delivering JSSLoader malware. JSSLoader is a remote access trojan (RAT) that was first observed in 2019 and is used by the GOLD NIAGARA cybercrime group.
Researchers report a new version of the JSSLoader remote access trojan being distributed via malicious Microsoft Excel addins.
After a months-long absence, the malware loader JSSLoader returned in June 2021 campaigns rewritten from the .NET programming language to C++. JSSLoader is often dropped in the first or second stage of a campaign and has the functionality to profile infected machines and load additional payloads.
After a months-long absence, the malware loader JSSLoader returned in June 2021 campaigns rewritten from the .NET programming language to C++. JSSLoader is often dropped in the first or second stage of a campaign and has the functionality to profile infected machines and load additional payloads.
The actor is known to distribute the JSSLoader malware, which facilitates access for the ransomware-as-a-service (RaaS) actor Sangria Tempest.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Storm-0324 manages a malware distribution chain and has used exploit kit and email-based vectors to deliver malware payloads.
The original delivery mechanism was unavailable for analysis, but the add-ins were reportedly delivered via invoice-themed emails. This approach is consistent with previous GOLD NIAGARA activity.
Earlier this year Morphisec and Secureworks described a new component used by this group, delivered in XLL format. That element was the first step in the attack chain leading to another malware, dubbed JSSLoader.
The JSSLoader RAT can harvest data about the compromised system and send it to a command and control (C2) server, run commands, download additional malicious payloads, and execute files.
Its commands and functionality focused on executing a next stage executable or JavaScript.
The .NET code lacks robust obfuscation, instead relying on variable .NET class and function names, simplistic encoding and decoding functions, a large number of unused strings, and string splitting/concatenation to avoid reliable detection.
In some cases, Storm-0324 uses protected documents for additional social engineering... The password also serves as an effective anti-analysis measure because it requires user interaction after launch.
The XLL files analyzed by CTU™ researchers use the ExcelDna.xll filename, possibly to mimic a legitimate Excel add-in project of the same name.
The threat actor regularly refreshes the User-Agent on the XLL files to evade EDRs that consolidate detection information from the entire network
The JSSLoader RAT can harvest data about the compromised system and send it to a command and control (C2) server... Once executed, JSSLoader collects basic system information, sends the information to the C2 server, and then waits for commands.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used by FIN7; observed performing system discovery via injected processes and execution of command-line utilities from non-standard parent processes.
A remote access trojan delivered via malicious Excel XLL add-ins. After execution, it downloads a JSSLoader binary, harvests system information, sends it to a C2 server, waits for commands, can run commands, download additional payloads, execute files, and uses Windows .lnk files for persistence.
A first-stage malware/loader distributed by Storm-0324 that facilitates access for Sangria Tempest and is followed by additional tooling, often as part of ransomware-linked intrusion chains.
A malware loader used by FIN7, described here as a rewritten version with expanded capabilities and new data exfiltration functions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.