Threat Intelligence

JSCeal Malware Steals Browser Sessions to Bypass Google Login Security

The Hacker News · 7 Sept 2026
Key Takeaway Australian small businesses should train staff to avoid downloading software from ads or unfamiliar links, and instead get trading, finance, or productivity tools only from official vendor websites.

Security researchers at Check Point have detailed how JSCeal, a heavily disguised piece of malware, is being used to harvest credentials, monitor victims, and intercept internet traffic. The malware hides its true purpose using multiple layers of code obfuscation, making it difficult for security tools to detect.

Victims are typically lured through fake online ads on platforms like Facebook and Google that redirect to counterfeit cryptocurrency trading websites. These sites trick users into downloading what appears to be a legitimate TradingView installer, which instead installs the malware. A related and separately identified campaign called SourTrade has used similar tactics, impersonating trusted trading and crypto brands and building the malicious code directly in the victim's computer memory rather than delivering a complete file, making it harder for network defences to spot.

These campaigns have been active since at least late 2024 and have targeted users in numerous countries, with a strong focus on the Asia Pacific and Latin America regions. Because the malware can capture browser session data, it may allow attackers to bypass login protections such as multi-factor authentication on services like Google, without needing the victim's password again.

Key Takeaway: Australian small businesses should train staff to avoid downloading software from ads or unfamiliar links, and instead get trading, finance, or productivity tools only from official vendor websites.

malware credential theft malvertising cryptocurrency scams browser security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.