logo

FIN7__2021__Morphisec_The_Evolution_of_the_FIN7_JssLoader.pdf

ID: 77e00485-9bdc-4a8b-8616-82316e4a1da8

STIX ID: report--77e00485-9bdc-4a8b-8616-82316e4a1da8

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2021-01-07

Last Modified Date: 2021-01-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive Summary Morphisec Labs documents a December 2020 FIN7 campaign that used phishing links to SharePoint to deliver VBScript/WSF droppers which staged a minimized .NET RAT called JSSLoader; JSSLoader collects host and AD information, persists via LNK shortcuts/scheduled tasks, accepts numerous remote commands (including in-memory PowerShell, DLL run, and auto-update), and can deliver a Takeout PowerShell that reflectively maps and executes Carbanak in memory. The report traces the malware's evolution, provides code excerpts showing anti-debugging and exfiltration behavior, and lists IOCs (hashes and C2 domains) to aid detection and response.