Beware of Malware infection in Facebook Ads Offering Cryptocurrency Rewards

Beware of Malware infection in Facebook Ads Offering Cryptocurrency Rewards
JSCEAL is being distributed through Facebook ads that impersonate a cryptocurrency exchange and lure users to fake installation pages that generate platform-specific installers for Windows and macOS. Over about two months, infections were confirmed on roughly 1,500 PCs in Korea, with attackers using BAT and PKG files, PowerShell, scheduled tasks, LaunchAgent persistence, and Node.js-based payload execution. #JSCEAL #Facebook #Binance #PowerShell #LaunchAgent

Keypoints

  • JSCEAL is a Node.js-based malware distributed through Facebook ads impersonating a cryptocurrency exchange.
  • Users are redirected to a fake exchange website that mimics a legitimate service with similar branding and live price data.
  • The site checks the victim’s operating system and generates different installer files for Windows and macOS.
  • On Windows, the attack uses a BAT file that launches PowerShell, downloads extra code, changes security settings, and creates persistence through scheduled tasks.
  • On macOS, the attack uses a PKG installer that downloads and runs shell scripts, prompts for a password, and can store the entered credentials.
  • JSCEAL infections were confirmed on about 1,500 PCs in Korea over the last two months.
  • Both Windows and macOS environments are targeted for follow-on command execution and additional JavaScript payload delivery.

MITRE Techniques

  • [T1189 ] Drive-by Compromise – Victims are lured through Facebook ads to a fake exchange site that delivers malicious installers (‘When a user clicks on the ad, they are redirected to a site that is disguised as a cryptocurrency exchange.’)
  • [T1059.001 ] PowerShell – Used in the Windows BAT loader to download and execute additional code (‘using PowerShell to download and execute additional code from an external source’)
  • [T1053.005 ] Scheduled Task/Job: Scheduled Task – Used to maintain persistence and trigger malware execution (‘It then modifies the system’s security settings and registers scheduled tasks’)
  • [T1112 ] Modify Registry – Security-related system settings are modified on Windows to weaken defenses (‘It then modifies the system’s security settings’)
  • [T1562.001 ] Impair Defenses: Disable or Modify Tools – Microsoft Defender exclusions are added to evade detection (‘it adds an exclusion to Microsoft Defender to evade detection’)
  • [T1027 ] Obfuscated Files or Information – The malware hides behind installer-like names and packed/compressed content (‘a BAT file that appears to be a legitimate installer’ / ‘downloads an additional compressed file, decompresses its contents’)
  • [T1204.002 ] User Execution: Malicious File – Users are tricked into running BAT or PKG installers from the fake site (‘generate installation files tailored to each operating system’)
  • [T1059.004 ] Unix Shell – A shell script is downloaded and executed on macOS (‘downloads and executes an additional shell script from an external server’)
  • [T1036 ] Masquerading – The malware and files impersonate legitimate exchange software and installer artifacts (‘disguised as a cryptocurrency exchange’ / ‘file name contains strings reminiscent of version numbers or installer names’)
  • [T1547.001 ] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder – macOS persistence is established through LaunchAgent registration (‘it then registers a LaunchAgent’)
  • [T1005 ] Data from Local System – System identification and clipboard data are collected from the victim machine (‘it transmits system identification information, clipboard data, the computer name’)
  • [T1071.001 ] Application Layer Protocol: Web Protocols – The malware communicates with external servers and a C2 server (‘communicates with the C2 server to receive additional commands’)
  • [T1056.001 ] Keylogging – The script captures the password entered into the disguised prompt and verifies it (‘prompts the user to enter their password’ / ‘verifies whether the entered password matches’)

Indicators of Compromise

  • [File names ] Windows and macOS installer artifacts – UsersPublicDesktopBinance.LNK, BAT installer file with version-like naming, PKG installer file with version-like naming
  • [File types ] Malware delivery and execution files – BAT, PKG, shell script, JavaScript, V8 bytecode
  • [Platform artifacts ] Persistence and execution traces – Microsoft Defender exclusions, scheduled tasks, LaunchAgent
  • [Domains / servers ] External infrastructure used to fetch payloads and send data – external source, external server, C2 server
  • [Browser / web artifacts ] Fake exchange delivery page – Facebook ad, disguised cryptocurrency exchange site
  • [System data collected ] Exfiltrated victim information – computer name, clipboard data, system identification information, PKG file name


Read more: https://asec.ahnlab.com/en/95645/