Fake Trading Apps Spread Malware Capable of Taking Over Accounts
What Happened
Cybersecurity researchers have detailed JSCeal, an advanced infostealer malware distributed through fake cryptocurrency and trading websites promoted via malicious online ads. The malware targets Chromium-based browsers, stealing credentials, cookies, OAuth tokens and other sensitive data. Researchers say attackers can use stolen browser session cookies to access already authenticated Google accounts without re-entering passwords or completing a new two-factor authentication (2FA) challenge.
Key Takeaways
2FA protects logins, but not stolen active sessions. Security experts warn that browser session theft is becoming a preferred tactic for cybercriminals, underscoring the importance of endpoint security and vigilance against fake software downloads and malicious ads.