JSSLoader is a Windows remote access trojan with payload-loading functionality, first observed in September 2019. It is associated with the financially motivated FIN7 group, also tracked as Sangria Tempest, ELBRUS, and Carbon Spider. Storm-0324, which overlaps with TA543 and Sagrid, distributes JSSLoader to establish access that can subsequently be transferred to ransomware operators. GOLD NIAGARA has also used the malware. Distribution campaigns have targeted organizations across finance, manufacturing, technology, retail, healthcare, education, and transportation.
JSSLoader profiles compromised hosts, collecting information about users, domains, drives, running processes, installed applications, network configuration, and desktop contents. It transmits collected information to command-and-control infrastructure and accepts commands to execute scripts, programs, and additional payloads. Its functionality includes data exfiltration, self-updating, and removal of the implant and its persistence. Observed variants establish persistence through startup shortcuts or registry run entries. Originally implemented in .NET, JSSLoader was rewritten in C++ for campaigns in June 2021; subsequent campaigns also used .NET variants. Evasion techniques include string encoding, runtime string reconstruction, changing identifiers, and system-uptime checks intended to hinder analysis.
Delivery commonly involves invoice-, payment-, or package-themed phishing emails containing malicious attachments or links to landing pages and SharePoint-hosted archives. Infection chains use obfuscated scripts, malicious Office documents, or Excel add-ins that download and execute the implant after user interaction. FIN7-linked campaigns have also used spearphishing. From July 2023, Storm-0324 expanded distribution to phishing messages sent through Microsoft Teams. JSSLoader provides an early foothold for additional tooling and downstream ransomware attacks rather than performing ransomware encryption itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The hosted file exploited a local security feature bypass vulnerability (CVE-2023-21715). Once the hosted file was launched, it drops the JSSLoader .Net payload in the victim machine, which later leads (hands-off the access) to Sangria Tempest’s RaaS (Ransomware as a Service) attack. | “Storm-0324 is distributing the JSSLoader before passing the buck to other ransomware groups.”
ELBRUS is responsible for developing and distributing multiple custom malware families used for persistence, including JSSLoader and Griffon.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Storm-0324 is distributing the JSSLoader before passing the buck to other ransomware groups.”
“Storm-0324 is distributing the JSSLoader before passing the buck to other ransomware groups.”
Researchers report a new version of the JSSLoader remote access trojan being distributed via malicious Microsoft Excel addins.
After a months-long absence, the malware loader JSSLoader returned in June 2021 campaigns rewritten from the .NET programming language to C++. JSSLoader is often dropped in the first or second stage of a campaign and has the functionality to profile infected machines and load additional payloads.
After a months-long absence, the malware loader JSSLoader returned in June 2021 campaigns rewritten from the .NET programming language to C++. JSSLoader is often dropped in the first or second stage of a campaign and has the functionality to profile infected machines and load additional payloads.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Storm-0324 manages a malware distribution chain and has used exploit kit and email-based vectors to deliver malware payloads.
The original delivery mechanism was unavailable for analysis, but the add-ins were reportedly delivered via invoice-themed emails. This approach is consistent with previous GOLD NIAGARA activity.
Earlier this year Morphisec and Secureworks described a new component used by this group, delivered in XLL format. That element was the first step in the attack chain leading to another malware, dubbed JSSLoader.
The JSSLoader RAT can harvest data about the compromised system and send it to a command and control (C2) server, run commands, download additional malicious payloads, and execute files.
Its commands and functionality focused on executing a next stage executable or JavaScript.
The .NET code lacks robust obfuscation, instead relying on variable .NET class and function names, simplistic encoding and decoding functions, a large number of unused strings, and string splitting/concatenation to avoid reliable detection.
In some cases, Storm-0324 uses protected documents for additional social engineering... The password also serves as an effective anti-analysis measure because it requires user interaction after launch.
The XLL files analyzed by CTU™ researchers use the ExcelDna.xll filename, possibly to mimic a legitimate Excel add-in project of the same name.
The threat actor regularly refreshes the User-Agent on the XLL files to evade EDRs that consolidate detection information from the entire network
The JSSLoader RAT can harvest data about the compromised system and send it to a command and control (C2) server... Once executed, JSSLoader collects basic system information, sends the information to the C2 server, and then waits for commands.
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor distributed by Storm-0324 through phishing emails and, in July 2023, Microsoft Teams messages. The analyzed infection chain uses a SharePoint-hosted ZIP containing WSF and subsequently downloaded VBS scripts to deliver a .NET executable. JSSLoader collects and exfiltrates host information, establishes startup persistence, receives commands from C2, executes scripts and additional payloads, and supports updating or uninstalling itself. The article also mentions C++ development intended to evade detection. Compromised access is handed to Sangria Tempest for subsequent ransomware attacks; no specific downstream ransomware family is identified.
Used by FIN7; observed performing system discovery via injected processes and execution of command-line utilities from non-standard parent processes.
A remote access trojan delivered via malicious Excel XLL add-ins. After execution, it downloads a JSSLoader binary, harvests system information, sends it to a C2 server, waits for commands, can run commands, download additional payloads, execute files, and uses Windows .lnk files for persistence.
A first-stage malware/loader distributed by Storm-0324 that facilitates access for Sangria Tempest and is followed by additional tooling, often as part of ransomware-linked intrusion chains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.