Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

The Hacker News by The Hacker News
September 7, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.

“The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers,” Check Point Research said in a technical report published last week.

JSCeal was first documented by Check Point in July 2025, highlighting the threat actors’ use of fake cryptocurrency trading sites to which unsuspecting users are redirected via malicious ads on Facebook and Google. The counterfeit sites instruct them to download bogus installers for TradingView that lead to the deployment of the malware. The activity overlaps with a threat cluster under the monikers WEEVILPROXY and MeadowLocust.

Malvertising campaigns distributing the malware make use of two ZIP archives delivered via PowerShell: one containing the Node.js runtime and the other containing the main payload and other auxiliary components.

As recently as last month, ad security platform Confiant disclosed details of a massive malvertising operation codenamed SourTrade, which has been observed impersonating trusted trading and cryptocurrency brands, such as Solana, Luno, and TradingView, to serve lookalike portals with malicious JavaScript that instructs web browsers to assemble malware directly in memory.

The campaign is assessed to be active since late 2024, targeting retail traders and cryptocurrency investors across 12 countries in 25 languages, primarily in Asia Pacific and Latin America. Evidence indicates that the campaign overlaps with a JSCeal campaign described by Bitdefender in September 2025. 

“What makes SourTrade technically distinct is what happens on its landing page,” Confiant said. “It does not distribute finished malware. Instead, it delivers assembly instructions to the victim’s browser, retrieves a clean legitimate file from separate infrastructure, and directs the browser to build the final malware in memory on the victim’s machine. No finished malware ever exists on the network.” 

JSCeal is protected using javascript-obfuscator, with the operators repeatedly using four groups of transformations to obscure the malware. These include –

  • Replacing function and variable names with short or nonsensical identifiers
  • Splitting important strings into chunks (which are subsequently encoded and RC4-protected) and then reconstructing them through decoder functions
  • Using control-flow flattening to turn program flow into a flat, single-level switch statement controlled by an infinite loop and a state variable with the goal of making analysis and reverse‑engineering harder
  • Forwarding function calls through proxy helpers and wrapping simple operations, like addition, subtraction, comparison, or function invocation, in dedicated helper functions

The Israeli cybersecurity company said it developed a “fully static deobfuscation pipeline” to decode compiled V8 JavaScript bytecode protected with the utility, thereby offering insights into the malware’s execution flow and its features, counting its ability to enumerate installed browsers, and query saved secrets, cookies, OAuth tokens, and other data from them, as well as “router” functions that register handlers for the collected information.

The browser stealing module targets a long list of Chromium-based browsers, such as Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc. For each browser, the malware navigates to the expected location of its user-data directory and lists available profiles, from where cookies and passwords are extracted.

What’s more, JSCeal is equipped to leverage the stolen cookie data to reconstruct a browser session and conduct active session replay attacks to bypass authentication and gain unauthorized access to a victim’s Google account. A second module embedded within the malware offers surveillance capabilities by recording keystrokes and taking screenshots.

“A common technique used by banking trojans is to install a local proxy and inject or modify web content in selected services,” Check Point said. “JSCeal follows a similar pattern: the recovered code shows proxy setup, certificate generation and installation, and service-specific request and response modification.”

“The proxy is not limited to passive interception. The recovered code contains dedicated handlers that modify selected requests and responses for specific services. A configuration function exposes separate overrides for Binance, Bybit, and Ledger, as well as generic handlers for replacing HTML, blocking hosts, and clearing selected cookies.”

There also exist multiple handlers specifically focused on cryptocurrency platforms, one of which captures account data and records cryptocurrency balances.

“JSCeal combines two forms of analysis friction: a version-specific compiled V8 format and several layers of JavaScript obfuscation applied before compilation. Neither makes the malware impossible to reverse, but together they move it outside the workflows that analysts normally rely on,” security researcher Aleksandra “Hasherezade” Doniec said. 

“Taken together, these developments show that the JSCeal authors are investing both in making the payload harder to analyze and in broadening its platform coverage. With campaigns continuing into recent months, the changes indicate that JSCeal remains under active development.”



Source link

The Hacker News

The Hacker News

Next Post

EZVIZ revela en IFA 2026 la próxima dirección hacia la seguridad del hogar inteligente, ilimitada y flexible

Recommended.

UScellular Announces Expected Amount of Special Dividend

UScellular Announces Expected Amount of Special Dividend

July 25, 2025
CHIGEE Launches XR-1: A Screen-Free Motorcycle Dash Cam That Records Every Ride and Speaks Up When It Counts

CHIGEE Launches XR-1: A Screen-Free Motorcycle Dash Cam That Records Every Ride and Speaks Up When It Counts

June 5, 2026

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026

Goldman Sachs picks China stocks poised to benefit from a new wave of AI-related hardware exports

August 16, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
Sohu.com to Report Second Quarter 2026 Financial Results on August 10, 2026

Sohu.com to Report Second Quarter 2026 Financial Results on August 10, 2026

July 31, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio