JSCeal Replays Google Sessions After Malvertising

Check Point says JSCeal is an active malvertising-delivered malware family that can steal browser credentials, replay Google session cookies, and intercept crypto-related traffic. The campaign uses fake trading-download lures, including bogus TradingView installers, to get the malware onto victims' machines. The trick is session theft, not password guessing: once JSCeal captures a browser cookie, it can present that cookie as proof the user is already signed in and act as the account holder. That means password changes and MFA do not necessarily end the takeover if the live browser session is still valid. For Google-account users, SaaS sign-ins, and trading platforms, the exposure sits in the browser session itself. If a service trusts cookies as the login state, an attacker who steals them can keep operating until that session is revoked, even when credentials were never reused.

Part of the PlainSec briefing for 2026-09-07

Every edition of this story: JSCeal Replays Google Sessions After Malvertising

Sources