Cybersecurity researchers have identified JSCeal, a sophisticated JavaScript-based malware targeting cryptocurrency investors through malicious advertisements and fake trading platforms to steal sensitive browser data and credentials.
Key Points
- JSCeal uses advanced obfuscation techniques, including control-flow flattening and RC4-protected strings, to evade detection and complicate reverse-engineering efforts.
- The malware is distributed via malvertising campaigns on platforms like Facebook and Google, often masquerading as legitimate TradingView installers.
- Once active, the malware extracts cookies, passwords, and OAuth tokens from various Chromium-based browsers, including Chrome, Edge, and Brave.
- JSCeal features surveillance capabilities, such as keystroke logging and screenshot capture, alongside a local proxy to intercept and modify web traffic.
- The malware specifically targets cryptocurrency users by monitoring account balances and modifying requests for platforms like Binance, Bybit, and Ledger.