Technology

Fake Trading Apps Spread Malware Capable of Taking Over Accounts

Published: 7 September 2026 · 1 min read

What Happened

Cybersecurity researchers have detailed JSCeal, an advanced infostealer malware distributed through fake cryptocurrency and trading websites promoted via malicious online ads. The malware targets Chromium-based browsers, stealing credentials, cookies, OAuth tokens and other sensitive data. Researchers say attackers can use stolen browser session cookies to access already authenticated Google accounts without re-entering passwords or completing a new two-factor authentication (2FA) challenge.

Key Takeaways

2FA protects logins, but not stolen active sessions. Security experts warn that browser session theft is becoming a preferred tactic for cybercriminals, underscoring the importance of endpoint security and vigilance against fake software downloads and malicious ads.

Sources

Thehackernews, Cyberwebspider