The Banloader, as it is called, is usually introduced by a phishing method the researcher said Brazilians are experts at. Victims have been found in Brazil, Spain, Portugal, the U.S., Argentina and Mexico. The attack is based on a Java archive (JAR), which can be run on OS X, Linux and Windows. The JAR files can be encrypted to hide their true nature. The dropper can also use proxy auto-config files that contain JavaScript functions.”]
Source: https://securityintelligence.com/news/java-malware-becomes-a-cross-platform-threat/

