JSSLoader: the shellcode edition
released on 2022-08-19 @ 11:05:21 AM
Security researchers observed a malspam campaign in late June attributed to the FIN7 APT group. One of the samples was also reported on Twitter; during execution, it was observed to drop a secondary payload, written in .NET. Earlier this year, a new component used by this group was identified, delivered in XLL format. That element was the first step in the attack chain leading to another malware, dubbed JSSLoader.