Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SOLAR SPIDER

Description

SOLAR SPIDER’s phishing campaigns deliver the JSOutProx RAT to financial institutions across Africa, the Middle East, South Asia and Southeast Asia.

AI Analysis

· 1 week ago

Executive Summary

SOLAR SPIDER is a cyber threat actor targeting financial institutions across Africa, the Middle East, South Asia, and Southeast Asia through phishing campaigns delivering the JSOutProx RAT. Their activities are increasingly sophisticated, leveraging known malware and infrastructure to compromise sensitive financial systems.

Goals & Targeting

SOLAR SPIDER's strategic objectives appear to be financial gain, likely through data exfiltration, unauthorized transactions, or other revenue-generating activities. The targeting of financial institutions aligns with this goal, as these entities hold sensitive customer information and are critical to national economies. The actor focuses on regions where financial systems may have weaker defenses or where geopolitical factors make them attractive targets.

Enhanced Description

SOLAR SPIDER operates with a primary focus on financially motivated cyberattacks, specifically targeting financial institutions in regions where banking systems are critical yet potentially vulnerable to exploitation. The actor's modus operandi involves deploying phishing emails that deliver the JSOutProx Remote Access Trojan (RAT), enabling unauthorized access and control over compromised systems. This activity is aimed at extracting sensitive information or conducting malicious operations within targeted networks. Recent intelligence indicates that SOLAR SPIDER has evolved its tactics, including the use of GitLab abuse for Command and Control (C2) communication, to enhance operational stealth and persistence.

Key Capabilities

  • Phishing campaign orchestration
  • Deployment of JSOutProx RAT for unauthorized access
  • GitLab abuse for C2 communication
  • Spear-phishing with malicious attachments or links

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access

ATT&CK Techniques

T1059.003
T1078.001
T1566.003
T1530
T1042

Software / Tooling

JSOutProx RAT
Custom phishing tools

Campaigns & Victims

SOLAR SPIDER's campaigns demonstrate a focus on specific regions and industries, with patterns indicating prolonged驻留 in targeted networks. The use of GitLab abuse for C2 communication suggests an attempt to blend malicious activity with legitimate services, reducing detection chances. Notable operations include the targeting of financial institutions in APAC and MENA regions, leveraging phishing emails and malicious links to deliver their payload.

IOC Patterns

  • Spear-phishing emails with malicious Office documents or links
  • MD5 hashes associated with JSOutProx RAT files
  • C2 communication via GitLab-associated domains
  • Specific IP ranges and domain names used for C2

Recommended Actions

  • Implement email filtering and phishing detection solutions
  • Monitor for异常 network traffic and C2 communications
  • Deploy endpoint detection and response (EDR) systems to detect RAT activity
  • Conduct regular employee training on phishing awareness
  • Harden banking system perimeters with multi-layered security

Suggested Tags

APT
financial-sector
South-Asia
Southeast-Asia
cyber-criminal
RAT

Confidence Assessment

Confidence in SOLAR SPIDER's activity is high due to observed patterns and linked campaigns. However, gaps exist regarding the full scope of their TTPs, exact APT designation, and long-term campaign objectives beyond immediate financial gain.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 5 IPv4 Address 4 URL 6 MD5 Hash 5

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

32

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
Phishing
Backdoor / C2
APT
financial-sector
South-Asia
Southeast-Asia
cyber-criminal
RAT

Details

Type
Criminal
Confidence
70%
Added
May 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.