TF-MAL-jar.pronsis_loader
📛 Threat Title
Malware family: Pronsis Loader
Description
ThreatFox malware family `jar.pronsis_loader`. Printable name: Pronsis Loader.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.netmanageit.com
A new malware called Pronsis Loader has been discovered, with similarities to D3F@ck Loader . Both use JPHP-compiled executables, but Pronsis uses NSIS for installation instead of Inno Setup.
-
web:hivepro.com
Analyze Traffic to Malicious IPs: Use network monitoring to detect traffic to malicious domains and IPs linked to known malware servers. Look for connections attempting to contact command-and-control (C2) servers associated with malware like Pronsis Loader , SUNSPINNER, and PURESTEALER.
-
web:malpedia.caad.fkie.fraunhofer.de
Pronsis Loader Propose Change According to TrustWave, this is a loader leveraging JPHP, which was observed fetching Latrodectus and Lumma.
-
web:thecyberwire.com
Shawn Kanady, Global Director of Trustwave SpiderLabs, to discuss their work on " Pronsis Loader : A JPHP-Driven Malware Diverging from D3F@ck Loader ." Trustwave SpiderLabs has uncovered Pronsis Loader , a new malware variant using the rare programming language JPHP and stealthy installation tactics to evade detection. The malware is capable of delivering high-risk payloads like Lumma Stealer and ...
-
web:www.anvilogic.com
When installed, these programs result in the download of various commodity malware families," according to Google Threat Intelligence Group. On Windows systems, UNC5812 employs a malware chain beginning with Pronsis Loader , which facilitates downloading a decoy mapping application, SUNSPINNER, and the final payload, PURESTEALER.
-
web:www.broadcom.com
Pronsis Loader is a new malware variant leveraged recently in campaigns delivering Lumma Stealer and Latrodectus payloads. The malware utilizes executables compiled in JPHP programming language, which is a Java implementation of PHP. Pronsis also uses Nullsoft Scriptable Install System (NSIS) for the deployments in the observed campaigns.
-
web:www.cubix.co
A JPHP-powered malware , Pronsis Loader , has emerged as a massive threat to businesses protecting their applications and platforms using traditional detection methods. Cybercriminals constantly introduce new methods and technologies to breach defenses and compromise systems. The discovery of a new custom malware loader , dubbed Pronsis Loader , highlights how attackers utilize advanced techniques ...
-
web:www.levelblue.com
Trustwave's Threat Intelligence team has discovered a new malware dubbed Pronsis Loader , with its earliest known variant dating back to November 2023.
-
web:www.techradar.com
JPHP - a rare choice in cybercrime Pronsis Loader can evade signature-based detection systems, which are typically designed to recognize more common programming languages in malware .
-
web:www.vcindi.com
Meanwhile, Pronsis Loader's adaptability signals an increasing complexity in malware deployment tactics. As cybersecurity threats evolve, awareness of these tools and their potential impact is essential for organizations and individuals alike to protect against the growing cyber threat landscape.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.