Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
JSCeal Malware Advances in Bypassing Google Security

JSCeal Malware Advances in Bypassing Google Security

Posted on September 7, 2026 By CWS

Cybersecurity experts have delved into JSCeal, a complex malware created using V8 JavaScript, revealing its capabilities in stealing credentials, monitoring activities, and intercepting web traffic. This malware stands out for its sophisticated approach to bypassing Google’s authentication protocols.

Advanced Obfuscation Techniques

JSCeal employs intricate obfuscation strategies to protect its payloads, as detailed by Check Point Research. These techniques include using RC4 encryption, control-flow flattening, and proxy functions to complicate analysis and reverse engineering. JSCeal was first brought to light by Check Point in July 2025, in connection with malicious cryptocurrency trading websites promoted through deceptive ads on major platforms like Facebook and Google.

The malware’s distribution involves malvertising campaigns, which employ two ZIP files delivered via PowerShell. These contain the Node.js runtime and the main payload, allowing for seamless execution once deployed on a target system.

Malvertising Campaigns and Global Impact

Recent findings by Confiant revealed a large-scale malvertising operation named SourTrade, which impersonates well-known cryptocurrency brands to deliver malware through lookalike sites. This operation has been targeting retail traders and cryptocurrency investors since late 2024, and shows significant overlap with the JSCeal campaigns.

Unlike traditional malware, SourTrade’s landing pages provide assembly instructions to the victim’s browser, which then retrieves legitimate files from separate sources to construct malware directly in memory. This method ensures no complete malware file is ever present on the network, making detection challenging.

Impact on Browser Security and User Data

JSCeal targets a variety of Chromium-based browsers, such as Google Chrome and Microsoft Edge, to extract cookies and passwords. It uses stolen cookies to re-establish browser sessions, facilitating session replay attacks that circumvent authentication measures and give unauthorized access to Google accounts.

Additionally, the malware’s surveillance capabilities include keystroke logging and screenshot capture. A local proxy setup allows for the modification of web content, with handlers for specific services, including cryptocurrency platforms like Binance and Bybit.

Ongoing Development and Future Concerns

The ongoing development of JSCeal, featuring both version-specific V8 formats and multilayered obfuscation, highlights its creators’ commitment to enhancing its complexity and reach. As the malware evolves, it continues to pose a significant threat to cybersecurity globally, warranting vigilant monitoring and advanced defensive measures from security professionals.

The Hacker News Tags:browser security, Check Point, Confiant, credential theft, Cryptocurrency, cyber threats, Cybersecurity, Google, JSCEAL, Malvertising, Malware, Obfuscation, session cookies, session replay attack, traffic interception

Post navigation

Previous Post: Critical Cybersecurity Developments: Chrome Zero-Day, AI Threats
Next Post: Russian Hackers Exploit HOOKEDGE Backdoor in Europe

Related Posts

New HTTP/2 ‘MadeYouReset’ Vulnerability Enables Large-Scale DoS Attacks New HTTP/2 ‘MadeYouReset’ Vulnerability Enables Large-Scale DoS Attacks The Hacker News
Microsoft Eliminates Malicious Edge Extensions with Hidden Malware Microsoft Eliminates Malicious Edge Extensions with Hidden Malware The Hacker News
Threat Actor Mimo Targets Magento and Docker to Deploy Crypto Miners and Proxyware Threat Actor Mimo Targets Magento and Docker to Deploy Crypto Miners and Proxyware The Hacker News
New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy The Hacker News
Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability The Hacker News
Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Telerik Vulnerability Chain Allows Remote Code Execution
  • Urgent N-able Hotfix Addresses Critical Security Flaw
  • OpenAI Develops Framework for AI Misalignment Disclosure
  • Russian Hackers Exploit HOOKEDGE Backdoor in Europe
  • JSCeal Malware Advances in Bypassing Google Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Telerik Vulnerability Chain Allows Remote Code Execution
  • Urgent N-able Hotfix Addresses Critical Security Flaw
  • OpenAI Develops Framework for AI Misalignment Disclosure
  • Russian Hackers Exploit HOOKEDGE Backdoor in Europe
  • JSCeal Malware Advances in Bypassing Google Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark