JSCEAL is being distributed through Facebook ads that impersonate a cryptocurrency exchange and lure users to fake installation pages that generate platform-specific installers for Windows and macOS. Over about two months, infections were confirmed on roughly 1,500 PCs in Korea, with attackers using BAT and PKG files, PowerShell, scheduled tasks, LaunchAgent persistence, and Node.js-based payload execution. #JSCEAL #Facebook #Binance #PowerShell #LaunchAgent
Keypoints
- JSCEAL is a Node.js-based malware distributed through Facebook ads impersonating a cryptocurrency exchange.
- Users are redirected to a fake exchange website that mimics a legitimate service with similar branding and live price data.
- The site checks the victimâs operating system and generates different installer files for Windows and macOS.
- On Windows, the attack uses a BAT file that launches PowerShell, downloads extra code, changes security settings, and creates persistence through scheduled tasks.
- On macOS, the attack uses a PKG installer that downloads and runs shell scripts, prompts for a password, and can store the entered credentials.
- JSCEAL infections were confirmed on about 1,500 PCs in Korea over the last two months.
- Both Windows and macOS environments are targeted for follow-on command execution and additional JavaScript payload delivery.
MITRE Techniques
- [T1189 ] Drive-by Compromise â Victims are lured through Facebook ads to a fake exchange site that delivers malicious installers (âWhen a user clicks on the ad, they are redirected to a site that is disguised as a cryptocurrency exchange.â)
- [T1059.001 ] PowerShell â Used in the Windows BAT loader to download and execute additional code (âusing PowerShell to download and execute additional code from an external sourceâ)
- [T1053.005 ] Scheduled Task/Job: Scheduled Task â Used to maintain persistence and trigger malware execution (âIt then modifies the systemâs security settings and registers scheduled tasksâ)
- [T1112 ] Modify Registry â Security-related system settings are modified on Windows to weaken defenses (âIt then modifies the systemâs security settingsâ)
- [T1562.001 ] Impair Defenses: Disable or Modify Tools â Microsoft Defender exclusions are added to evade detection (âit adds an exclusion to Microsoft Defender to evade detectionâ)
- [T1027 ] Obfuscated Files or Information â The malware hides behind installer-like names and packed/compressed content (âa BAT file that appears to be a legitimate installerâ / âdownloads an additional compressed file, decompresses its contentsâ)
- [T1204.002 ] User Execution: Malicious File â Users are tricked into running BAT or PKG installers from the fake site (âgenerate installation files tailored to each operating systemâ)
- [T1059.004 ] Unix Shell â A shell script is downloaded and executed on macOS (âdownloads and executes an additional shell script from an external serverâ)
- [T1036 ] Masquerading â The malware and files impersonate legitimate exchange software and installer artifacts (âdisguised as a cryptocurrency exchangeâ / âfile name contains strings reminiscent of version numbers or installer namesâ)
- [T1547.001 ] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder â macOS persistence is established through LaunchAgent registration (âit then registers a LaunchAgentâ)
- [T1005 ] Data from Local System â System identification and clipboard data are collected from the victim machine (âit transmits system identification information, clipboard data, the computer nameâ)
- [T1071.001 ] Application Layer Protocol: Web Protocols â The malware communicates with external servers and a C2 server (âcommunicates with the C2 server to receive additional commandsâ)
- [T1056.001 ] Keylogging â The script captures the password entered into the disguised prompt and verifies it (âprompts the user to enter their passwordâ / âverifies whether the entered password matchesâ)
Indicators of Compromise
- [File names ] Windows and macOS installer artifacts â UsersPublicDesktopBinance.LNK, BAT installer file with version-like naming, PKG installer file with version-like naming
- [File types ] Malware delivery and execution files â BAT, PKG, shell script, JavaScript, V8 bytecode
- [Platform artifacts ] Persistence and execution traces â Microsoft Defender exclusions, scheduled tasks, LaunchAgent
- [Domains / servers ] External infrastructure used to fetch payloads and send data â external source, external server, C2 server
- [Browser / web artifacts ] Fake exchange delivery page â Facebook ad, disguised cryptocurrency exchange site
- [System data collected ] Exfiltrated victim information â computer name, clipboard data, system identification information, PKG file name
Read more: https://asec.ahnlab.com/en/95645/