JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Key Points:
- Cybersecurity researchers have uncovered JSCeal, a sophisticated compiled V8 JavaScript malware designed for credential harvesting, surveillance, and traffic interception, protected by advanced obfuscation techniques including RC4 encryption and control-flow flattening.
- JSCeal is distributed via malvertising campaigns that redirect users to fake cryptocurrency trading sites, prompting them to download bogus TradingView installers that deploy the malware; these campaigns overlap with known threat clusters like WEEVILPROXY and MeadowLocust.
- The malware targets a wide range of Chromium-based browsers to extract cookies, passwords, OAuth tokens, and other saved data, enabling session replay attacks to bypass authentication and access victims' Google accounts.
- JSCeal includes proxy capabilities that intercept and modify web traffic for specific cryptocurrency platforms such as Binance, Bybit, and Ledger, allowing it to capture account data and manipulate service requests and responses.
- Researchers highlight that JSCeal’s combination of compiled V8 bytecode and layered JavaScript obfuscation complicates analysis and reverse engineering, indicating ongoing active development and efforts to broaden platform coverage.