JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
-
Researchers have detailed a new strain of compiled V8 JavaScript malware dubbed JSCeal, which is capable of bypassing Google authentication through the theft of session cookies.
The malicious payloads are heavily obfuscated using javascript-obfuscator, employing a layered approach to evade analysis. Key protection mechanisms observed by Check Point Research include:
- RC4-protected strings to conceal data
- Control-flow flattening to disrupt code analysis
- Proxy functions to obscure function calls
- Operation wrappers to further complicate reverse engineering
JSCeal's capabilities extend beyond simple credential theft, encompassing broader surveillance and traffic-interception functions. The malware is compiled for the V8 JavaScript engine, a departure from typical script-based threats, which allows it to operate with greater stealth and complexity.
Source: The Hacker News
Given the malware's reliance on stolen session cookies rather than traditional credential phishing, how is your organization monitoring for suspicious session anomalies in Google Workspace?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login