FIN7__2021__Morphisec_The_Evolution_of_the_FIN7_JssLoader.pdf
ID: 77e00485-9bdc-4a8b-8616-82316e4a1da8
STIX ID: report--77e00485-9bdc-4a8b-8616-82316e4a1da8
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2021-01-07
Last Modified Date: 2021-01-07
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive Summary
Morphisec Labs documents a December 2020 FIN7 campaign that used phishing links to SharePoint to deliver VBScript/WSF droppers which staged a minimized .NET RAT called JSSLoader; JSSLoader collects host and AD information, persists via LNK shortcuts/scheduled tasks, accepts numerous remote commands (including in-memory PowerShell, DLL run, and auto-update), and can deliver a Takeout PowerShell that reflectively maps and executes Carbanak in memory. The report traces the malware's evolution, provides code excerpts showing anti-debugging and exfiltration behavior, and lists IOCs (hashes and C2 domains) to aid detection and response.
