Researchers Reveal JSCeal Stealer Capabilities Using Static V8 Bytecode Deobfuscation

· Original article ↗

Summary

Check Point researchers developed a static pipeline to deobfuscate JSCeal’s compiled V8 bytecode, revealing credential theft, keylogging, surveillance, and HTTPS interception. They also document newer payload encryption, V8 version changes, and macOS targeting.

Key points

  • JSCeal is a cryptocurrency-focused stealer delivered as compiled V8 bytecode and executed through a bundled Node.js runtime.
  • Check Point’s static pipeline recovered analyzable output from 23 payloads without executing the malware; the toolkit is publicly available.
  • The recovered code shows browser credential, cookie, and token theft, keylogging, screenshot capture, and Telegram account targeting.
  • JSCeal can install a locally generated root certificate and use an HTTPS interception proxy to modify service traffic.
  • From November 2025, newer campaigns added AES-256-CBC encryption around the Brotli-compressed payload and moved to a newer, version-sensitive V8 runtime.
  • The researchers report more recent developments including V8 code caches for newer Node.js versions and macOS targeting.

Article Details

Attack Vectors
  • Malvertising initiates a delivery chain involving multiple PowerShell scripts that download a bundled Node.js runtime and the final malware bundle.
  • A JavaScript launcher decompresses the Brotli-compressed payload and loads compiled V8 bytecode through the bundled Node.js runtime.
  • Payload protection combines compiled bytecode, RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers.
  • Newer payloads add AES-256-CBC encryption whose key is supplied by an earlier deployment stage through an environment variable.
  • Browser theft reads profile databases and decrypts saved passwords and cookies using DPAPI and App-Bound encryption keys.
  • Browser automation replays recovered cookies, tries passwords stolen from the same host, and implements a workflow for obtaining Google OAuth tokens with ANDROID scope.
  • A local HTTPS interception proxy installs an attacker-controlled root certificate and modifies selected cryptocurrency-service requests and responses.
  • Recovered surveillance functionality includes keyboard capture, screenshots, and enumeration and manipulation of visible windows.
  • Collected application secrets, wallet mnemonics, and other records reach a network client using binary HTTPS POST requests and WebSocket connections.
Defensive Notes
  • The released static pipeline decompresses the payload, disassembles it with a compatible V8 build, and applies ordered View8 deobfuscation passes without executing the malware.
  • V8 code caches are version-sensitive. The released end-to-end setup targets 10.2.154.26-node.25; support for 13.6.233.10-node.28 was planned.
  • Recover strings before control-flow unflattening and proxy resolution because recovered strings expose dictionary keys and dispatcher ordering.
  • Treat LLM-generated function names as hypotheses; validate behavior using function bodies, strings, APIs, paths, and data flow.
  • Hunting only for the .jsc extension misses later payloads renamed to app.js.
  • An isolated encrypted payload may be insufficient for analysis because its AES key must be recovered from the surrounding deployment chain.
  • Static recovery exposes capability branches that may not execute during a particular sandbox run.

Indicators of compromise

TypeIndicatorContext
MD503f4e47b9c2283c32bb8f8f042ce6e41Brotli-compressed JSCeal payload in Appendix B.
MD509dbfac09f9cafdbc7d225eb144f0e69Unpacked JSCeal payload in Appendix B.
MD50b8015cbb1ffdc6efe6a306ff5b1115fBrotli-compressed JSCeal payload in Appendix B.
MD50d1fce0cb2b9dec26a10f0822aeffb19Last observed JSCeal payload using V8 10.2.154.26-node.25; associated with activity beginning in late October 2025.
MD51026743185dfa10e9ddc21b5a4c578d5Brotli-compressed JSCeal payload in Appendix B.
MD510c576a57fc040eddd84d631786b8ddaUnpacked JSCeal payload in Appendix B.
MD513823095b8d31013ba41a5c98ce69b59Unpacked JSCeal payload in Appendix B.
MD51b7f4288b12373c8d6488fde69c8ce0dUnpacked JSCeal payload in Appendix B.
MD5201f28b5e62e52e269757930f941c774Brotli-compressed JSCeal payload in Appendix B.
MD52477fd3e348c51bf575ede398253d0b3Unpacked JSCeal payload in Appendix B.
MD52841170a19c028c16990cdcc6fd499bcUnpacked JSCeal payload in Appendix B.
MD52fe27eb8c99626e8c02e4bfd02aca962Brotli-compressed JSCeal payload in Appendix B.
MD530f23bb28ce56584f8f098ff0035b029Unpacked JSCeal payload in Appendix B.
MD5376ec4dbc3363fa7131367e4c6327a46Brotli-compressed JSCeal payload in Appendix B.
MD5454fb012cdd0736e4ed41fabf0916f46Unpacked JSCeal payload in Appendix B.
MD5462195f7f8033df7371e899fe9bc51deBrotli-compressed JSCeal payload in Appendix B.
MD5469c60508d4470bc1cc5e4a70d0e7112Unpacked JSCeal payload in Appendix B.
MD5499184635d56a9827d2059256a35e530Brotli-compressed JSCeal payload in Appendix B.
MD5533d0b93ea03cd5bab4eec0f0ebadd03Brotli-compressed JSCeal payload in Appendix B.
MD5576e94d705bd50811dc9525a45732bc3Unpacked JSCeal payload in Appendix B.
MD5581e2e2265d0c1509b3799c5a9039374First observed AES-encrypted JSCeal payload, generated on 2025-11-11.
MD56626b8caf2734c83a93f78d31b703584Unpacked JSCeal payload in Appendix B.
MD568ac84a8470d1f365f0bb2f37b6256d5Brotli-compressed JSCeal payload in Appendix B.
MD56e023b9b3097a2dba311cb06a91fe259Brotli-compressed JSCeal payload in Appendix B.
MD5710cc97e64618c68ffca72ac405a48a1Unpacked JSCeal payload in Appendix B.
MD57650ec266b414d097101da12c4384659Unpacked JSCeal case-study payload in Appendix B.
MD57b659fa5c93af29c4e11d8c8be437058Brotli-compressed JSCeal payload in Appendix B.
MD58fb3e6acb2024601eba0ba484091ff3dBrotli-compressed JSCeal payload in Appendix B.
MD591038aebe528a065c3e995a418db6826Unpacked older JSCeal payload using the simpler string-obfuscation variant.
MD5975319142460fc43e3dc5e495d2313c9Unpacked JSCeal payload in Appendix B.
MD5a2aa25f0d5b23a2897576e4cf9596a7cUnpacked JSCeal payload in Appendix B.
MD5a308fa1524c9d5b8dc55d2b296a2629bUnpacked JSCeal payload in Appendix B.
MD5a6f5bb2b8a3e1abe332dd40e50d78aa3Unpacked JSCeal payload in Appendix B.
MD5af105a6d4dc10b2bfefd75e917245523Brotli-compressed JSCeal payload in Appendix B.
MD5b2dad3f88b7f6870f83eb1ad852b7f7eBrotli-compressed JSCeal payload in Appendix B.
MD5c605371a8caf11497f1879597292e338Unpacked JSCeal payload in Appendix B.
MD5c8db5e53572e68349c76107f03544491Unpacked JSCeal payload in Appendix B.
MD5cd7afa032d5f5be0db037edb617f438bUnpacked JSCeal payload in Appendix B.
MD5d064dfaaef30c057b832c79996c35e89Brotli-compressed JSCeal payload in Appendix B.
MD5d5b4137135cf121e3ea07b1c81fe1108Brotli-compressed JSCeal payload in Appendix B.
MD5de10c6b3dc4619f59bc9c80a0aa15e6aJSCeal payload associated with macOS targeting.
MD5e26687982d924ffebef6fbf2d9d43350Brotli-compressed JSCeal payload in Appendix B.
MD5e27ae65977287bdfb7b0e15fd3603f85Brotli-compressed JSCeal payload selected for the detailed capability case study.
MD5e57f6ca6543616f75f7811273616fe47Unpacked JSCeal payload in Appendix B.
MD5e711a90b5ece5380e1acaed56827e8d5Brotli-compressed JSCeal payload in Appendix B.
MD5e81b35b76b4d97751c0724bc0c7f3b83Unpacked JSCeal payload in Appendix B.
MD5e8b5448b4f7b013e8c6191b20d3f8291Brotli-compressed JSCeal payload in Appendix B.
MD5fa0180946b9a6ad373b7a8f983e2e597Unpacked JSCeal payload in Appendix B.
MD5fd4494c555adda2eb54b88f5c9c08801Brotli-compressed JSCeal payload in Appendix B.
SHA256058ae4136e241f116d8c5b1a1cad15b53090797154539faa35706568fbd85d9bBrotli-compressed JSCeal payload in Appendix B.
SHA25605db78bff1a48a674e70368b96a550a5f9f93271eb261ab63b36ee37e0e8b9f8Brotli-compressed JSCeal payload in Appendix B.
SHA25606dce0f294c62f2a2393c812ff711bde831bf420a4df484bcf5b6241fc0f00d0Unpacked JSCeal payload in Appendix B.
SHA25609f803f69bde280adbd4e584ed26a01affac9721db8c5730275d385f084b422aDistribution bundle for a JSCeal payload in Appendix B.
SHA2560c31453e74a3b763c7aea550b4f5f194e7656226012b243221eb93fa22da118eBrotli-compressed JSCeal payload in Appendix B.
SHA2560c72513efdae9785894b6e925590d0b59b652dda53b8cd882037a87e672a4a5aUnpacked JSCeal payload in Appendix B.
SHA25611e85a8306057945accc65395b780377c07d4ec9ae52d78185554bf1957e3caaUnpacked JSCeal payload in Appendix B.
SHA25618347a39f174c97947649b3f1de55e8409ff805e808f2101e5953a956e9ee99fDistribution bundle for a JSCeal payload in Appendix B.
SHA256192342a5e4fcfc5e8ec430427e1dfa773fd324e3d7215047f36f1114ef930f4eUnpacked JSCeal payload in Appendix B.
SHA2561b0efeb1d988b7bc11014ccc9fdff141fc16425d659f553f6cc6946872499667Brotli-compressed JSCeal payload in Appendix B.
SHA2561f5acba97db6d514e4b35ba0601c5269697e8ab3bb99d097db25ec7e74464594Brotli-compressed JSCeal payload in Appendix B.
SHA256212d21ed1c4b5bd9b9104e04f2876842b99cd17def3591df72781891d584dca0Brotli-compressed JSCeal payload in Appendix B.
SHA25622833568125bcc55000503cfe6b470925b7d095ff7592bef79fe52e0573123ccUnpacked JSCeal payload in Appendix B.
SHA2562c29b4089845b010428f8be48e62f165e0f7f8a48e58200629c6020c7ac2cab7Unpacked JSCeal payload in Appendix B.
SHA2562cf2d22d1317df6c49171be61ef35c4f6c3da17785fa73e68aa95109075f79bdUnpacked JSCeal payload in Appendix B.
SHA2562d42aa747f7ebc3280b14d30c6b71043545888946d9d6acd6abbaf4545841462Distribution bundle for a JSCeal payload in Appendix B.
SHA2562ef1ea37a941330a79a3056461e61992864e6e38c0f68cbb626ebf1f96e362c5Brotli-compressed JSCeal payload in Appendix B.
SHA25631b38e76ccaca6f38168b4fdd9cbdedd8efa7e65fe6090240e281bd3152a6febBrotli-compressed JSCeal payload in Appendix B.
SHA25636d34b6405a33fcb95e1323e2ca8c688af02b315fc1bded19fa27bd1c7ca6f1cUnpacked JSCeal payload in Appendix B.
SHA256395f4c1562a1a8caeba254ccbc7d278b8194795ff5ad3824cfc0c566273835f0Unpacked JSCeal payload in Appendix B.
SHA2563d800b7dbdcb6874e29ddd2e9a1313f3d82b323e89a720c632c708098a7ca0e9Distribution bundle for a JSCeal payload in Appendix B.
SHA25643c57c60a8008e617b16dc6dab29372347ebe144f043200c106149c3106438baUnpacked JSCeal payload in Appendix B.
SHA2564757f3d26bc7110e9c7f4da8050afc2ed661cd92aec9cf7d301d9b9b24e0b668Brotli-compressed JSCeal payload in Appendix B.
SHA256484da78b0fef35711f86876f7c1c77264b8e4295d7393369379c384c05337ec5Brotli-compressed JSCeal payload in Appendix B.
SHA256504345099ba4c77cbb4224101794e525f2bc9adb40904159195c17d7e345085eUnpacked JSCeal payload in Appendix B.
SHA25655ee2359b12fbce928532d1d4efcfbbbd63340502d0107466c803d6517b44437Distribution bundle for a JSCeal payload in Appendix B.
SHA25657f32b3942d5543177f07e49fc84f1409a49b5df7d25549e543607c223b87695Unpacked JSCeal case-study payload in Appendix B.
SHA25659c9038227c634f4e512afaa98f2ca998b0aaac83437c218686c51acbda7873eUnpacked JSCeal payload in Appendix B.
SHA2565a024ae97242be3b1b954f845f7a87a1411c47830f81a2b54f47ec2cf741e2a0Distribution bundle for a JSCeal payload in Appendix B.
SHA2565b4edd9bffdd7909b8b432eacd463d59eb23eba151c9e218161ab15dd72d55edBrotli-compressed JSCeal payload in Appendix B.
SHA2565f071a36c0a79ddce92824a49fd8e9bd048b87cabb635671073402365afc342aBrotli-compressed JSCeal payload in Appendix B.
SHA2565fe810cb5b34c8fd07c7eca301b32ef2d3b86290828d67edaad8444db811f20bDistribution bundle for a JSCeal payload in Appendix B.
SHA2566075cd41edb59c43c13aa3591e054cdb127b17bf34e036dae591244ea2f8868fUnpacked JSCeal payload in Appendix B.
SHA25662ba626bce09db5f8750938edced3768b401084a7d6584cd6ff9d53d2517781dBrotli-compressed JSCeal payload in Appendix B.
SHA25667e3d7bcdf4cfd25750425ac0682e0ed98b3cb473448696fb79bf311fcdb18cdDistribution bundle for a JSCeal payload in Appendix B.
SHA256684aabefe516539cda48c65cb08014e6eb645b4f1e668d159fe0c18cf74eb407Distribution bundle for a JSCeal payload in Appendix B.
SHA2566b498ec73d32860202b6a6ff8d21f8b5216c3903e066136f9d69ef2969955a78Distribution bundle for a JSCeal payload in Appendix B.
SHA256742ad2dd3d2444bd3758b6e46dd76f9c43dfaae03bdffc3598ce7d8ab3cd3ac5Unpacked JSCeal payload in Appendix B.
SHA2567e1c82cdcff73ac69fee3ba71d67353a062103f1bfae4f263d03b3b84e48d782Distribution bundle for a JSCeal payload in Appendix B.
SHA2567f3e73b2e0ebea3eaffa3685e0a162d10fde388282060d9e35b173b743676916Distribution bundle for a JSCeal payload in Appendix B.
SHA25682f8215c7e68f4a6b656b7dc6638982a6625c662ce6d6a05330eefbfde2637acBrotli-compressed JSCeal payload in Appendix B.
SHA25684db0663b6aa8df2ac04470288fd5528f5537fb89d78a2e01cabdce371a686e8Distribution bundle for a JSCeal payload in Appendix B.
SHA25688b1d75d330cf6be9a7f48cdfd51c48125a86f9bcb6bcb736fb8399e0617d680Unpacked JSCeal payload in Appendix B.
SHA2568abffe0d13d3b93ca3469045e4cebbee25b3631e6bba13880f04b7c8acac2536Brotli-compressed JSCeal payload in Appendix B.
SHA2568b3ed808822479eb62d78d819db35362e4e79138ac82310d30e0c351a17992b6Unpacked JSCeal payload in Appendix B.
SHA2568c674f58b157a7319b564bb774e7aeb35135d615511838e4a553fe7ea9e94759Distribution bundle for a JSCeal payload in Appendix B.
SHA2568d389f56c5b71d194bddd5b6ce5906e7e22730034ad882606cc8ae701011bf8cBrotli-compressed JSCeal payload in Appendix B.
SHA25694191824bb5062622663e2434d2b749a8c936eb573aaac23594dee8dda304731Unpacked JSCeal payload in Appendix B.
SHA25695b39a0bad021f33e08df042b02d3267faee7bbc3e3080dda295c35b464dd607Brotli-compressed JSCeal payload in Appendix B.
SHA2569615f60ea3cc1c65eb8fe6d77bb85fe6b455503193eab02310a873fccadd332eDistribution bundle for the JSCeal case-study payload.
SHA25699b8124c2a64d26567f19a44618144b1d6a7501a5892918f0120a496f983a0f2Distribution bundle for a JSCeal payload in Appendix B.
SHA2569b5359dc99501ef2a4667d265e9b032f76dc28c97437a463965e2168d20e5c38Brotli-compressed JSCeal payload in Appendix B.
SHA2569f673e3b361f438e9986f2a7b2423d3d02dbecea0c220163566850ef6ab56626Unpacked JSCeal payload in Appendix B.
SHA256acdaba94e9975e8e03fa13bae7f0f93f165f42226aeecea3af5a4e0111bdfb7eDistribution bundle for a JSCeal payload in Appendix B.
SHA256aec3e252c429e150c42976d6badeea31e48a0356ecbd27796df83fc6d3de16eaUnpacked JSCeal payload in Appendix B.
SHA256b3f76851a8e55a967029be7ffe4c15afd63656d6946a3df77206455e5ac28ea1Distribution bundle for a JSCeal payload in Appendix B.
SHA256b73c3d732bb6bff8b9088cc0dcbadb35eea0802056324f1b6295cb9277c62755Brotli-compressed JSCeal case-study payload in Appendix B.
SHA256b90e3aaae14e7787e5ea4a6d4beee672049bd5eb05427f2c80b64f605860d2b8Distribution bundle for a JSCeal payload in Appendix B.
SHA256c12ac711b4ceaa17a4e48b16fca7dabd615e4eaf35bb65fe9131ceac1687095aBrotli-compressed JSCeal payload in Appendix B.
SHA256c13fcb214a576401cd624dacf248480c38b8bcbb85e5d3da52cc204a61395d14Unpacked JSCeal payload in Appendix B.
SHA256c288e79ed9d1fb654a341b92d878a3165a09fb21dfa826f3559b46738fdbbdebUnpacked older JSCeal payload in Appendix B.
SHA256c77b3b7a507162bfc03cfeb8ef18d5ee7017e8fcbd6d7e005f986a3c967b8d45Distribution bundle for a JSCeal payload in Appendix B.
SHA256caf8bfc90e4300b8a18c3fe3a4badbe44c106830e7432d8eea227857a790ec91Brotli-compressed JSCeal payload in Appendix B.
SHA256cfdb3bb9edea8de7c7a70275a2b8689619276f1e5f2b8805e67ceab1ee252f6dUnpacked JSCeal payload in Appendix B.
SHA256dc561df51d27ed3a99cb916bf08452c901956778c26709e69705cbdf77f74816Distribution bundle for a JSCeal payload in Appendix B.
SHA256dd2bb7316be55446aebfa31d05e57e936eb9a18d5d9c20d60d87493100d05fe6Distribution bundle for a JSCeal payload in Appendix B.
SHA256de213ebc44c614d0b2324787e267183dbbbbb19e1ad866435a322ee00e24e7b6Brotli-compressed JSCeal payload in Appendix B.
SHA256f6c670e65765d10a5ca0205a6ece3a3e6c7c730b0a8534c5adef4a3cbf06eb9cDistribution bundle for a JSCeal payload in Appendix B.
SHA256f720d6f6baebd4ef76df978f2678387385ee2d20a37423e7957c2341fe46f9caBrotli-compressed JSCeal payload in Appendix B.
SHA256fa02e707af9a353f0e2d7a77489c11c2249a1d9dbccf74070130b31834e8d7c3Unpacked JSCeal payload in Appendix B.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationJSCeal uses RC4-protected strings, control-flow flattening, proxy functions, operation wrappers, and compiled V8 bytecode to obstruct analysis.T1027.013 · Encrypted/Encoded FileNewer JSCeal payloads wrap Brotli-compressed bytecode in AES-256-CBC encryption, with the key supplied by an earlier deployment stage.T1036 · MasqueradingLater payloads were renamed from app.jsc to app.js despite remaining V8 code caches, making them resemble ordinary application files.T1041 · Exfiltration Over C2 ChannelCollected secrets and wallet mnemonics are passed through save handlers to the malware's HTTPS and WebSocket network client.T1056.001 · KeyloggingThe recovered surveillance module initializes keyboard capture and exposes a keydown subscription.T1059.001 · PowerShellThe delivery chain uses multiple PowerShell scripts to download archives and launch the bundled Node.js runtime; recovered strings also show hidden PowerShell execution.T1059.007 · JavaScriptA JavaScript launcher runs before the JSCeal payload, which executes as compiled V8 bytecode under Node.js.T1071.001 · Web ProtocolsThe network client uses HTTPS binary POST requests and secure WebSocket connections to RPC endpoints with machineId and token parameters.T1105 · Ingress Tool TransferPowerShell downloads node.zip and build.zip containing the runtime, malware payload, and supporting components.T1113 · Screen CaptureThe surveillance module exposes a screenshot handler backed by recovered screen-capture functionality.T1134.001 · Token Impersonation/TheftA security worker invokes impersonateUserSecurity before attaching its router; DPAPI operations can also run under the browser user's security context.T1140 · Deobfuscate/Decode Files or InformationThe launcher decompresses the Brotli payload; newer encrypted payloads additionally require a deployment-provided AES key before bytecode recovery.T1518 · Software DiscoveryRecovered functionality enumerates installed applications and discovers installed browsers and their profiles.T1528 · Steal Application Access TokenThe implemented Google authentication workflow retrieves oauth_token cookies and saves resulting OAuth tokens with ANDROID scope.T1539 · Steal Web Session CookieJSCeal reads browser Network\Cookies databases and decrypts encrypted cookie values into usable session records.T1550.004 · Web Session CookieBrowser automation injects cookies recovered from victim profiles and uses them to reconstruct authenticated Google sessions.T1553.004 · Install Root CertificateJSCeal writes a generated attacker-controlled certificate to a temporary file and uses certutil -addstore -f root to install it.T1555.003 · Credentials from Web BrowsersJSCeal queries browser Login Data databases and decrypts saved passwords using DPAPI-derived or App-Bound keys.T1557 · Adversary-in-the-MiddleJSCeal configures a local HTTPS interception proxy and modifies selected cryptocurrency-service requests and responses.

People

Malware

Vendors

Products

ASCENDEXASCENDEXAvast Secure BrowserIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.Binance"binance"BraveIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.BybitA configuration function exposes separate overrides for Binance, Bybit, and Ledger, as well as generic handlers for replacing HTML, blocking hosts, and clearing selected cookies.Claude Sonnet 4.6For the final comparison, we generated names from the same normalized deobfuscated base using Claude Sonnet 4.6 and GPT-5.4-mini.Cốc CốcIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.COINHUBCOINHUBCOINSPHCOINSPHCSGOEMPIRECSGOEMPIREDIGIFINEXDIGIFINEXFMCPAYFMCPAYFORTUNO_MARKETSFORTUNO_MARKETSGATEIOGATEIOGoogle ChromeIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.GPT-5.4-miniFor the final comparison, we generated names from the same normalized deobfuscated base using Claude Sonnet 4.6 and GPT-5.4-mini.HATAHATAHTXHTXI3QI3QKCEXKCEXKrakenFor example, Kraken is one of the targeted services.KUCOINKUCOINLedgerA configuration function exposes separate overrides for Binance, Bybit, and Ledger, as well as generic handlers for replacing HTML, blocking hosts, and clearing selected cookies.macOSWe conclude with a brief look at more recent JSCeal developments, including V8 code caches generated for a newer Node.js/V8 version, an additional payload-encryption layer, and macOS targeting.MEXCMEXCMicrosoft EdgeIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.Microsoft Windowswinpty-agent.exe – an agent for a hidden Windows console (open source)Node.jsWe conclude with a brief look at more recent JSCeal developments, including V8 code caches generated for a newer Node.js/V8 version, an additional payload-encryption layer, and macOS targeting.NOONESNOONESOKXOKXOperaIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.Opera GXIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.PAXFULPAXFULPIONEXPIONEXPOLONIEXPOLONIEXREMITANOREMITANOTelegramIt also queries all installed applications and targets Telegram accounts:TOKOCRYPTOTOKOCRYPTOUBITEXUBITEXVivaldiIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.

Tools

Industries

Related Articles