As cited
Copy frozen at (site build).
threat intel
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Researchers documented JSCeal, a compiled JavaScript malware with capabilities for credential harvesting, surveillance, and network traffic interception. The malware employs multiple obfuscation techniques, including RC4-protected strings and control-flow flattening, to evade detection.
Why it matters: Organizations and developers need to monitor for JSCeal distribution vectors and review authentication controls, as the malware can steal session cookies and potentially bypass multifactor authentication (MFA) protections.
- Source published
- First seen by Cybersecurity Tracker