hacker-news · Crawled Sep 7, 2026
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
3 IoCs 1 Malware
Read original article ↗
AI Summary
JSCeal is a compiled V8 JavaScript malware designed to steal browser credentials, cookies, and OAuth tokens, enabling attackers to bypass Google authentication via session replay attacks. It is distributed through malvertising campaigns, particularly the SourTrade operation, which impersonates legitimate cryptocurrency trading platforms like TradingView, Solana, and Luno. The malware uses heavy obfuscation techniques and in-memory assembly to avoid detection, and includes modules for keystroke logging, screenshot capture, and traffic interception via a local proxy targeting financial and cryptocurrency services.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 3 extracted
MITRE ATT&CK TTPs 12 techniques
T1003 OS Credential Dumping · Credential Access T1003.001 LSASS Memory · Credential Access T1005 Data from Local System · Collection T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1204.002 Malicious File · Execution T1555 Credentials from Password Stores · Credential Access T1555.003 Credentials from Web Browsers · Credential Access