Todd Faulk
Published on: April 9, 2024
The China-linked Solar Spider cybercriminal group recently rolled out malware targeting Saudi financial institutions, expanding from its traditional operating areas in Southeast Asia and India. Resecurity, a cybersecurity firm familiar with Solar Spiderās tactics, reported the new cyberattack campaign in early April.
Resecurity discovered that a new version of Solar Spiderās infamous JSOutProx malware was used in February to target an undisclosed Saudi regional bank and its customers. The attack began with a phishing email posing as a SWIFT funds transfer notification. Once a bank employee clicked on an attached PDF file, JSOutProx was able to enter the bankās customer files through a JavaScript backdoor.
The malicious program then collected customer account information and credentials and targeted customers with similar phishing emails, this time using fake Moneygram transfer notices. Once hooked, the customerās bank accounts could be drained.
The newest version of the malware is very flexible and adapts itself to the victimās circumstances. āDepending on the victimās environment, it goes right in and then actually bleeds them or poisons the environment, depending on what plug-ins are enabled,ā reported Gene Yoo, the CEO of Resecurity.
JSOutProx is well known in the financial industry of the Asia-Pacific region and is constantly evolving. The malware has been used to attack the customers of financial institutions in Taiwan, the Philippines, Singapore, India, and more recently, the Middle East, often changing tactics in each country.
āThe JSOutProx malware poses a serious threat to financial institutions around the world, and especially those in the [Asia-Pacific] region as those entities have been more frequently targeted with this malware,ā Visa said in its biannual threats report.
The JSOutProx remote access Trojan (RAT) ācan run shell commands, download, upload, and execute files, manipulate the file system, establish persistence, take screenshots, and manipulate keyboard and mouse events,ā Visa stated in its report. āThese unique features allow the malware to evade detection by security systems and obtain a variety of sensitive payment and financial information from targeted financial institutionsā and their customers.
- SEO Powered Content & PR Distribution. Get Amplified Today.
- PlatoData.Network Vertical Generative Ai. Empower Yourself. Access Here.
- PlatoAiStream. Web3 Intelligence. Knowledge Amplified. Access Here.
- PlatoESG. Carbon, CleanTech, Energy, Environment, Solar, Waste Management. Access Here.
- PlatoHealth. Biotech and Clinical Trials Intelligence. Access Here.
- Source: https://www.safetydetectives.com/news/solar-spider-expands-malware-attacks-to-saudi-arabia/
- :has
- :is
- 40
- 9
- a
- Able
- access
- Account
- Accounts
- actually
- adapts
- allow
- an
- and
- April
- ARE
- areas
- around
- AS
- asia
- attack
- Attacks
- avatar
- backdoor
- Bank
- bank accounts
- BE
- been
- began
- by
- Campaign
- ceo
- changing
- circumstances
- constantly
- could
- country
- Credentials
- customer
- Customers
- Cyberattack
- CYBERCRIMINAL
- Cybersecurity
- Depending
- Detection
- discovered
- download
- drained
- each
- Early
- East
- emails
- Employee
- enabled
- Enter
- entities
- Environment
- especially
- establish
- evade
- events
- evolving
- execute
- expanding
- expands
- fake
- familiar
- Features
- February
- File
- Files
- financial
- financial information
- Financial institutions
- Firm
- flexible
- frequently
- from
- funds
- Goes
- Group
- Have
- HTTPS
- in
- india
- industry
- infamous
- information
- institutions
- IT
- ITS
- itself
- JavaScript
- known
- malicious
- malware
- Middle
- Middle East
- MoneyGram
- more
- New
- Newest
- notification
- obtain
- of
- often
- on
- once
- operating
- or
- out
- payment
- persistence
- Philippines
- phishing
- plato
- Plato Data Intelligence
- PlatoData
- poses
- posing
- Program
- RAT
- recently
- region
- regional
- remote
- remote access
- report
- Reported
- right
- Rolled
- Run
- Said
- Saudi
- Saudi Arabia
- screenshots
- security
- sensitive
- serious
- Shell
- similar
- Singapore
- solar
- southeast
- Southeast Asia
- stated
- SWIFT
- system
- Systems
- tactics
- Taiwan
- Take
- Target
- targeted
- targeting
- that
- The
- The Philippines
- the world
- their
- Them
- then
- this
- those
- threat
- threats
- Through
- time
- to
- todd
- traditional
- transfer
- Trojan
- unique
- used
- using
- variety
- version
- very
- visa
- was
- webp
- WELL
- What
- with
- world
- zephyrnet