Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Mar 06, 2022 | Updated Nov 22, 2023

TrojanSpy:MSIL/JSSLoader.B

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

TrojanSpy:MSIL/JSSLoader.B represents the Microsoft intermediate language (MSIL) portion of JSSLoader. This often functions as the second-stage loader in malware operations.

Its primary functions include collecting a wide array of system information and transmitting it back to the command and control (C2) server.

Additionally, it maintains communication with the C2 server to retrieve and deploy additional payloads as necessary.

 

The following actions must be taken to mitigate the damage:

  1. Remove the infected devices from the network.
  2. Check the network for other compromised machines.

 

Microsoft Defender Antivirus automatically removes threats as they are identified. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts.

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.

Devices infected by this trojan might be severely compromised and require complete restoration. Consider restoring your device. When restoring data, ensure that it is a clean, uninfected copy.

Follow us