SOLAR SPIDER’s phishing campaigns deliver the JSOutProx RAT to financial institutions across Africa, the Middle East, South Asia and Southeast Asia.
Executive Summary
SOLAR SPIDER is a cyber threat actor targeting financial institutions across Africa, the Middle East, South Asia, and Southeast Asia through phishing campaigns delivering the JSOutProx RAT. Their activities are increasingly sophisticated, leveraging known malware and infrastructure to compromise sensitive financial systems.
Goals & Targeting
SOLAR SPIDER's strategic objectives appear to be financial gain, likely through data exfiltration, unauthorized transactions, or other revenue-generating activities. The targeting of financial institutions aligns with this goal, as these entities hold sensitive customer information and are critical to national economies. The actor focuses on regions where financial systems may have weaker defenses or where geopolitical factors make them attractive targets.
Enhanced Description
SOLAR SPIDER operates with a primary focus on financially motivated cyberattacks, specifically targeting financial institutions in regions where banking systems are critical yet potentially vulnerable to exploitation. The actor's modus operandi involves deploying phishing emails that deliver the JSOutProx Remote Access Trojan (RAT), enabling unauthorized access and control over compromised systems. This activity is aimed at extracting sensitive information or conducting malicious operations within targeted networks. Recent intelligence indicates that SOLAR SPIDER has evolved its tactics, including the use of GitLab abuse for Command and Control (C2) communication, to enhance operational stealth and persistence.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
SOLAR SPIDER's campaigns demonstrate a focus on specific regions and industries, with patterns indicating prolonged驻留 in targeted networks. The use of GitLab abuse for C2 communication suggests an attempt to blend malicious activity with legitimate services, reducing detection chances. Notable operations include the targeting of financial institutions in APAC and MENA regions, leveraging phishing emails and malicious links to deliver their payload.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in SOLAR SPIDER's activity is high due to observed patterns and linked campaigns. However, gaps exist regarding the full scope of their TTPs, exact APT designation, and long-term campaign objectives beyond immediate financial gain.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
32
IOCs
0
Observed Data
0
Tactics