Product
macOS
- First Reported
- Sep 8, 2026
- Latest Reported
- Sep 29, 2026
Reported Context (3)
- Over the past two months, JSCEAL infections have been confirmed on approximately 1,500 PCs in Korea, with both Windows and macOS systems included as Attack Targets. JSCEAL Malware Spread Through Fake Cryptocurrency Exchange Ads on Facebook
- It decrypts a hidden C2 address and then fetches an encrypted payload tailored to Windows or macOS victims. Google Ads Deliver Fake Tech-Support Lockers Impersonating Microsoft Defender and Apple
- Windows, it retrieves code from 0x46790e2Ac7F3CA5a7D1bfCe312d11E91d23383Ff and if the victim is running macOS, it uses 0x68DcE15C1002a2689E19D33A3aE509DD1fEb11A5. The response is Base64 decoded and evaluated as ClearFake WebDAV Chains Deliver Amatera, ZigCryptoStealer and Unauthorized NetSupport
Malware (6)
Threat Actors (1)
MITRE ATT&CK (22)
Vendors (4)
Products (9)
Tools (3)
Industries (1)
Countries (10)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.