Researchers Reveal JSCeal Stealer Capabilities Using Static V8 Bytecode Deobfuscation

Summary
Check Point researchers developed a static pipeline to deobfuscate JSCeal’s compiled V8 bytecode, revealing credential theft, keylogging, surveillance, and HTTPS interception. They also document newer payload encryption, V8 version changes, and macOS targeting.
Key points
- JSCeal is a cryptocurrency-focused stealer delivered as compiled V8 bytecode and executed through a bundled Node.js runtime.
- Check Point’s static pipeline recovered analyzable output from 23 payloads without executing the malware; the toolkit is publicly available.
- The recovered code shows browser credential, cookie, and token theft, keylogging, screenshot capture, and Telegram account targeting.
- JSCeal can install a locally generated root certificate and use an HTTPS interception proxy to modify service traffic.
- From November 2025, newer campaigns added AES-256-CBC encryption around the Brotli-compressed payload and moved to a newer, version-sensitive V8 runtime.
- The researchers report more recent developments including V8 code caches for newer Node.js versions and macOS targeting.
Article Details
- Attack Vectors
- Malvertising initiates a delivery chain involving multiple PowerShell scripts that download a bundled Node.js runtime and the final malware bundle.
- A JavaScript launcher decompresses the Brotli-compressed payload and loads compiled V8 bytecode through the bundled Node.js runtime.
- Payload protection combines compiled bytecode, RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers.
- Newer payloads add AES-256-CBC encryption whose key is supplied by an earlier deployment stage through an environment variable.
- Browser theft reads profile databases and decrypts saved passwords and cookies using DPAPI and App-Bound encryption keys.
- Browser automation replays recovered cookies, tries passwords stolen from the same host, and implements a workflow for obtaining Google OAuth tokens with ANDROID scope.
- A local HTTPS interception proxy installs an attacker-controlled root certificate and modifies selected cryptocurrency-service requests and responses.
- Recovered surveillance functionality includes keyboard capture, screenshots, and enumeration and manipulation of visible windows.
- Collected application secrets, wallet mnemonics, and other records reach a network client using binary HTTPS POST requests and WebSocket connections.
- Defensive Notes
- The released static pipeline decompresses the payload, disassembles it with a compatible V8 build, and applies ordered View8 deobfuscation passes without executing the malware.
- V8 code caches are version-sensitive. The released end-to-end setup targets 10.2.154.26-node.25; support for 13.6.233.10-node.28 was planned.
- Recover strings before control-flow unflattening and proxy resolution because recovered strings expose dictionary keys and dispatcher ordering.
- Treat LLM-generated function names as hypotheses; validate behavior using function bodies, strings, APIs, paths, and data flow.
- Hunting only for the .jsc extension misses later payloads renamed to app.js.
- An isolated encrypted payload may be insufficient for analysis because its AES key must be recovered from the surrounding deployment chain.
- Static recovery exposes capability branches that may not execute during a particular sandbox run.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| MD5 | 03f4e47b9c2283c32bb8f8f042ce6e41 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | 09dbfac09f9cafdbc7d225eb144f0e69 | Unpacked JSCeal payload in Appendix B. |
| MD5 | 0b8015cbb1ffdc6efe6a306ff5b1115f | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | 0d1fce0cb2b9dec26a10f0822aeffb19 | Last observed JSCeal payload using V8 10.2.154.26-node.25; associated with activity beginning in late October 2025. |
| MD5 | 1026743185dfa10e9ddc21b5a4c578d5 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | 10c576a57fc040eddd84d631786b8dda | Unpacked JSCeal payload in Appendix B. |
| MD5 | 13823095b8d31013ba41a5c98ce69b59 | Unpacked JSCeal payload in Appendix B. |
| MD5 | 1b7f4288b12373c8d6488fde69c8ce0d | Unpacked JSCeal payload in Appendix B. |
| MD5 | 201f28b5e62e52e269757930f941c774 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | 2477fd3e348c51bf575ede398253d0b3 | Unpacked JSCeal payload in Appendix B. |
| MD5 | 2841170a19c028c16990cdcc6fd499bc | Unpacked JSCeal payload in Appendix B. |
| MD5 | 2fe27eb8c99626e8c02e4bfd02aca962 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | 30f23bb28ce56584f8f098ff0035b029 | Unpacked JSCeal payload in Appendix B. |
| MD5 | 376ec4dbc3363fa7131367e4c6327a46 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | 454fb012cdd0736e4ed41fabf0916f46 | Unpacked JSCeal payload in Appendix B. |
| MD5 | 462195f7f8033df7371e899fe9bc51de | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | 469c60508d4470bc1cc5e4a70d0e7112 | Unpacked JSCeal payload in Appendix B. |
| MD5 | 499184635d56a9827d2059256a35e530 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | 533d0b93ea03cd5bab4eec0f0ebadd03 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | 576e94d705bd50811dc9525a45732bc3 | Unpacked JSCeal payload in Appendix B. |
| MD5 | 581e2e2265d0c1509b3799c5a9039374 | First observed AES-encrypted JSCeal payload, generated on 2025-11-11. |
| MD5 | 6626b8caf2734c83a93f78d31b703584 | Unpacked JSCeal payload in Appendix B. |
| MD5 | 68ac84a8470d1f365f0bb2f37b6256d5 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | 6e023b9b3097a2dba311cb06a91fe259 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | 710cc97e64618c68ffca72ac405a48a1 | Unpacked JSCeal payload in Appendix B. |
| MD5 | 7650ec266b414d097101da12c4384659 | Unpacked JSCeal case-study payload in Appendix B. |
| MD5 | 7b659fa5c93af29c4e11d8c8be437058 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | 8fb3e6acb2024601eba0ba484091ff3d | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | 91038aebe528a065c3e995a418db6826 | Unpacked older JSCeal payload using the simpler string-obfuscation variant. |
| MD5 | 975319142460fc43e3dc5e495d2313c9 | Unpacked JSCeal payload in Appendix B. |
| MD5 | a2aa25f0d5b23a2897576e4cf9596a7c | Unpacked JSCeal payload in Appendix B. |
| MD5 | a308fa1524c9d5b8dc55d2b296a2629b | Unpacked JSCeal payload in Appendix B. |
| MD5 | a6f5bb2b8a3e1abe332dd40e50d78aa3 | Unpacked JSCeal payload in Appendix B. |
| MD5 | af105a6d4dc10b2bfefd75e917245523 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | b2dad3f88b7f6870f83eb1ad852b7f7e | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | c605371a8caf11497f1879597292e338 | Unpacked JSCeal payload in Appendix B. |
| MD5 | c8db5e53572e68349c76107f03544491 | Unpacked JSCeal payload in Appendix B. |
| MD5 | cd7afa032d5f5be0db037edb617f438b | Unpacked JSCeal payload in Appendix B. |
| MD5 | d064dfaaef30c057b832c79996c35e89 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | d5b4137135cf121e3ea07b1c81fe1108 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | de10c6b3dc4619f59bc9c80a0aa15e6a | JSCeal payload associated with macOS targeting. |
| MD5 | e26687982d924ffebef6fbf2d9d43350 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | e27ae65977287bdfb7b0e15fd3603f85 | Brotli-compressed JSCeal payload selected for the detailed capability case study. |
| MD5 | e57f6ca6543616f75f7811273616fe47 | Unpacked JSCeal payload in Appendix B. |
| MD5 | e711a90b5ece5380e1acaed56827e8d5 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | e81b35b76b4d97751c0724bc0c7f3b83 | Unpacked JSCeal payload in Appendix B. |
| MD5 | e8b5448b4f7b013e8c6191b20d3f8291 | Brotli-compressed JSCeal payload in Appendix B. |
| MD5 | fa0180946b9a6ad373b7a8f983e2e597 | Unpacked JSCeal payload in Appendix B. |
| MD5 | fd4494c555adda2eb54b88f5c9c08801 | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 058ae4136e241f116d8c5b1a1cad15b53090797154539faa35706568fbd85d9b | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 05db78bff1a48a674e70368b96a550a5f9f93271eb261ab63b36ee37e0e8b9f8 | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 06dce0f294c62f2a2393c812ff711bde831bf420a4df484bcf5b6241fc0f00d0 | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 09f803f69bde280adbd4e584ed26a01affac9721db8c5730275d385f084b422a | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | 0c31453e74a3b763c7aea550b4f5f194e7656226012b243221eb93fa22da118e | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 0c72513efdae9785894b6e925590d0b59b652dda53b8cd882037a87e672a4a5a | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 11e85a8306057945accc65395b780377c07d4ec9ae52d78185554bf1957e3caa | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 18347a39f174c97947649b3f1de55e8409ff805e808f2101e5953a956e9ee99f | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | 192342a5e4fcfc5e8ec430427e1dfa773fd324e3d7215047f36f1114ef930f4e | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 1b0efeb1d988b7bc11014ccc9fdff141fc16425d659f553f6cc6946872499667 | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 1f5acba97db6d514e4b35ba0601c5269697e8ab3bb99d097db25ec7e74464594 | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 212d21ed1c4b5bd9b9104e04f2876842b99cd17def3591df72781891d584dca0 | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 22833568125bcc55000503cfe6b470925b7d095ff7592bef79fe52e0573123cc | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 2c29b4089845b010428f8be48e62f165e0f7f8a48e58200629c6020c7ac2cab7 | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 2cf2d22d1317df6c49171be61ef35c4f6c3da17785fa73e68aa95109075f79bd | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 2d42aa747f7ebc3280b14d30c6b71043545888946d9d6acd6abbaf4545841462 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | 2ef1ea37a941330a79a3056461e61992864e6e38c0f68cbb626ebf1f96e362c5 | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 31b38e76ccaca6f38168b4fdd9cbdedd8efa7e65fe6090240e281bd3152a6feb | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 36d34b6405a33fcb95e1323e2ca8c688af02b315fc1bded19fa27bd1c7ca6f1c | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 395f4c1562a1a8caeba254ccbc7d278b8194795ff5ad3824cfc0c566273835f0 | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 3d800b7dbdcb6874e29ddd2e9a1313f3d82b323e89a720c632c708098a7ca0e9 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | 43c57c60a8008e617b16dc6dab29372347ebe144f043200c106149c3106438ba | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 4757f3d26bc7110e9c7f4da8050afc2ed661cd92aec9cf7d301d9b9b24e0b668 | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 484da78b0fef35711f86876f7c1c77264b8e4295d7393369379c384c05337ec5 | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 504345099ba4c77cbb4224101794e525f2bc9adb40904159195c17d7e345085e | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 55ee2359b12fbce928532d1d4efcfbbbd63340502d0107466c803d6517b44437 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | 57f32b3942d5543177f07e49fc84f1409a49b5df7d25549e543607c223b87695 | Unpacked JSCeal case-study payload in Appendix B. |
| SHA256 | 59c9038227c634f4e512afaa98f2ca998b0aaac83437c218686c51acbda7873e | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 5a024ae97242be3b1b954f845f7a87a1411c47830f81a2b54f47ec2cf741e2a0 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | 5b4edd9bffdd7909b8b432eacd463d59eb23eba151c9e218161ab15dd72d55ed | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 5f071a36c0a79ddce92824a49fd8e9bd048b87cabb635671073402365afc342a | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 5fe810cb5b34c8fd07c7eca301b32ef2d3b86290828d67edaad8444db811f20b | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | 6075cd41edb59c43c13aa3591e054cdb127b17bf34e036dae591244ea2f8868f | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 62ba626bce09db5f8750938edced3768b401084a7d6584cd6ff9d53d2517781d | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 67e3d7bcdf4cfd25750425ac0682e0ed98b3cb473448696fb79bf311fcdb18cd | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | 684aabefe516539cda48c65cb08014e6eb645b4f1e668d159fe0c18cf74eb407 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | 6b498ec73d32860202b6a6ff8d21f8b5216c3903e066136f9d69ef2969955a78 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | 742ad2dd3d2444bd3758b6e46dd76f9c43dfaae03bdffc3598ce7d8ab3cd3ac5 | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 7e1c82cdcff73ac69fee3ba71d67353a062103f1bfae4f263d03b3b84e48d782 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | 7f3e73b2e0ebea3eaffa3685e0a162d10fde388282060d9e35b173b743676916 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | 82f8215c7e68f4a6b656b7dc6638982a6625c662ce6d6a05330eefbfde2637ac | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 84db0663b6aa8df2ac04470288fd5528f5537fb89d78a2e01cabdce371a686e8 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | 88b1d75d330cf6be9a7f48cdfd51c48125a86f9bcb6bcb736fb8399e0617d680 | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 8abffe0d13d3b93ca3469045e4cebbee25b3631e6bba13880f04b7c8acac2536 | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 8b3ed808822479eb62d78d819db35362e4e79138ac82310d30e0c351a17992b6 | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 8c674f58b157a7319b564bb774e7aeb35135d615511838e4a553fe7ea9e94759 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | 8d389f56c5b71d194bddd5b6ce5906e7e22730034ad882606cc8ae701011bf8c | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 94191824bb5062622663e2434d2b749a8c936eb573aaac23594dee8dda304731 | Unpacked JSCeal payload in Appendix B. |
| SHA256 | 95b39a0bad021f33e08df042b02d3267faee7bbc3e3080dda295c35b464dd607 | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 9615f60ea3cc1c65eb8fe6d77bb85fe6b455503193eab02310a873fccadd332e | Distribution bundle for the JSCeal case-study payload. |
| SHA256 | 99b8124c2a64d26567f19a44618144b1d6a7501a5892918f0120a496f983a0f2 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | 9b5359dc99501ef2a4667d265e9b032f76dc28c97437a463965e2168d20e5c38 | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | 9f673e3b361f438e9986f2a7b2423d3d02dbecea0c220163566850ef6ab56626 | Unpacked JSCeal payload in Appendix B. |
| SHA256 | acdaba94e9975e8e03fa13bae7f0f93f165f42226aeecea3af5a4e0111bdfb7e | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | aec3e252c429e150c42976d6badeea31e48a0356ecbd27796df83fc6d3de16ea | Unpacked JSCeal payload in Appendix B. |
| SHA256 | b3f76851a8e55a967029be7ffe4c15afd63656d6946a3df77206455e5ac28ea1 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | b73c3d732bb6bff8b9088cc0dcbadb35eea0802056324f1b6295cb9277c62755 | Brotli-compressed JSCeal case-study payload in Appendix B. |
| SHA256 | b90e3aaae14e7787e5ea4a6d4beee672049bd5eb05427f2c80b64f605860d2b8 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | c12ac711b4ceaa17a4e48b16fca7dabd615e4eaf35bb65fe9131ceac1687095a | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | c13fcb214a576401cd624dacf248480c38b8bcbb85e5d3da52cc204a61395d14 | Unpacked JSCeal payload in Appendix B. |
| SHA256 | c288e79ed9d1fb654a341b92d878a3165a09fb21dfa826f3559b46738fdbbdeb | Unpacked older JSCeal payload in Appendix B. |
| SHA256 | c77b3b7a507162bfc03cfeb8ef18d5ee7017e8fcbd6d7e005f986a3c967b8d45 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | caf8bfc90e4300b8a18c3fe3a4badbe44c106830e7432d8eea227857a790ec91 | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | cfdb3bb9edea8de7c7a70275a2b8689619276f1e5f2b8805e67ceab1ee252f6d | Unpacked JSCeal payload in Appendix B. |
| SHA256 | dc561df51d27ed3a99cb916bf08452c901956778c26709e69705cbdf77f74816 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | dd2bb7316be55446aebfa31d05e57e936eb9a18d5d9c20d60d87493100d05fe6 | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | de213ebc44c614d0b2324787e267183dbbbbb19e1ad866435a322ee00e24e7b6 | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | f6c670e65765d10a5ca0205a6ece3a3e6c7c730b0a8534c5adef4a3cbf06eb9c | Distribution bundle for a JSCeal payload in Appendix B. |
| SHA256 | f720d6f6baebd4ef76df978f2678387385ee2d20a37423e7957c2341fe46f9ca | Brotli-compressed JSCeal payload in Appendix B. |
| SHA256 | fa02e707af9a353f0e2d7a77489c11c2249a1d9dbccf74070130b31834e8d7c3 | Unpacked JSCeal payload in Appendix B. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationJSCeal uses RC4-protected strings, control-flow flattening, proxy functions, operation wrappers, and compiled V8 bytecode to obstruct analysis.T1027.013 · Encrypted/Encoded FileNewer JSCeal payloads wrap Brotli-compressed bytecode in AES-256-CBC encryption, with the key supplied by an earlier deployment stage.T1036 · MasqueradingLater payloads were renamed from app.jsc to app.js despite remaining V8 code caches, making them resemble ordinary application files.T1041 · Exfiltration Over C2 ChannelCollected secrets and wallet mnemonics are passed through save handlers to the malware's HTTPS and WebSocket network client.T1056.001 · KeyloggingThe recovered surveillance module initializes keyboard capture and exposes a keydown subscription.T1059.001 · PowerShellThe delivery chain uses multiple PowerShell scripts to download archives and launch the bundled Node.js runtime; recovered strings also show hidden PowerShell execution.T1059.007 · JavaScriptA JavaScript launcher runs before the JSCeal payload, which executes as compiled V8 bytecode under Node.js.T1071.001 · Web ProtocolsThe network client uses HTTPS binary POST requests and secure WebSocket connections to RPC endpoints with machineId and token parameters.T1105 · Ingress Tool TransferPowerShell downloads node.zip and build.zip containing the runtime, malware payload, and supporting components.T1113 · Screen CaptureThe surveillance module exposes a screenshot handler backed by recovered screen-capture functionality.T1134.001 · Token Impersonation/TheftA security worker invokes impersonateUserSecurity before attaching its router; DPAPI operations can also run under the browser user's security context.T1140 · Deobfuscate/Decode Files or InformationThe launcher decompresses the Brotli payload; newer encrypted payloads additionally require a deployment-provided AES key before bytecode recovery.T1518 · Software DiscoveryRecovered functionality enumerates installed applications and discovers installed browsers and their profiles.T1528 · Steal Application Access TokenThe implemented Google authentication workflow retrieves oauth_token cookies and saves resulting OAuth tokens with ANDROID scope.T1539 · Steal Web Session CookieJSCeal reads browser Network\Cookies databases and decrypts encrypted cookie values into usable session records.T1550.004 · Web Session CookieBrowser automation injects cookies recovered from victim profiles and uses them to reconstruct authenticated Google sessions.T1553.004 · Install Root CertificateJSCeal writes a generated attacker-controlled certificate to a temporary file and uses certutil -addstore -f root to install it.T1555.003 · Credentials from Web BrowsersJSCeal queries browser Login Data databases and decrypts saved passwords using DPAPI-derived or App-Bound keys.T1557 · Adversary-in-the-MiddleJSCeal configures a local HTTPS interception proxy and modifies selected cryptocurrency-service requests and responses.
People
Malware
Vendors
Products
ASCENDEXASCENDEXAvast Secure BrowserIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.Binance"binance"BraveIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.BybitA configuration function exposes separate overrides for Binance, Bybit, and Ledger, as well as generic handlers for replacing HTML, blocking hosts, and clearing selected cookies.Claude Sonnet 4.6For the final comparison, we generated names from the same normalized deobfuscated base using Claude Sonnet 4.6 and GPT-5.4-mini.Cốc CốcIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.COINHUBCOINHUBCOINSPHCOINSPHCSGOEMPIRECSGOEMPIREDIGIFINEXDIGIFINEXFMCPAYFMCPAYFORTUNO_MARKETSFORTUNO_MARKETSGATEIOGATEIOGoogle ChromeIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.GPT-5.4-miniFor the final comparison, we generated names from the same normalized deobfuscated base using Claude Sonnet 4.6 and GPT-5.4-mini.HATAHATAHTXHTXI3QI3QKCEXKCEXKrakenFor example, Kraken is one of the targeted services.KUCOINKUCOINLedgerA configuration function exposes separate overrides for Binance, Bybit, and Ledger, as well as generic handlers for replacing HTML, blocking hosts, and clearing selected cookies.macOSWe conclude with a brief look at more recent JSCeal developments, including V8 code caches generated for a newer Node.js/V8 version, an additional payload-encryption layer, and macOS targeting.MEXCMEXCMicrosoft EdgeIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.Microsoft Windowswinpty-agent.exe – an agent for a hidden Windows console (open source)Node.jsWe conclude with a brief look at more recent JSCeal developments, including V8 code caches generated for a newer Node.js/V8 version, an additional payload-encryption layer, and macOS targeting.NOONESNOONESOKXOKXOperaIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.Opera GXIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.PAXFULPAXFULPIONEXPIONEXPOLONIEXPOLONIEXREMITANOREMITANOTelegramIt also queries all installed applications and targets Telegram accounts:TOKOCRYPTOTOKOCRYPTOUBITEXUBITEXVivaldiIn the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc.
Tools
certutilThen, it installs a locally generated, attacker-controlled root certificate onto the victim machine, first dropping it as a temporary file, and then using certutil to add it to the local store.ghost-cursorIt also uses ghost-cursor to perform some of the page interactions.javascript-obfuscatorThe payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers.jsc_deobfuscatorThe complete toolkit is publicly available at jsc_deobfuscator.PuppeteerThe implementation uses Puppeteer together with puppeteer-extra.puppeteer-extraThe implementation uses Puppeteer together with puppeteer-extra.View8CPR developed a fully static deobfuscation pipeline that transforms View8 pseudocode without executing the malware.