New JSCEAL Infostealer Malware Attacking Windows Systems to Steal Login Credentials
ID: 7d1c19dc-20cd-505f-aeed-2991062ce9e3
STIX ID: report--7d1c19dc-20cd-505f-aeed-2991062ce9e3
Feed Name: cybersecurityNews.com
JSCEAL is an active Windows information-stealer observed since mid-2025 that spreads via deceptive ads linking to fake websites and malicious installers; operators revamped their infrastructure in August 2025 to use single-word C2 domains and implemented advanced evasion (PowerShell user-agent gating, fake PDF responses, COM-based scheduling, multi-format payload delivery), increasing its stealth and analysis resistance—organisations are advised to monitor PowerShell activity, block suspicious C2 communications, and educate users about malvertising.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
