Learn
active
JSCeal Malware Harvests Session Cookies to Bypass Google Auth
- Engineer — Learn: JSCeal’s session-cookie theft technique is a reminder to enforce short-lived tokens, device-bound sessions, and strict cookie flags (HttpOnly/Secure/SameSite), but no specific software to patch is identified and enrichment signals are absent.
- SOC/IR — Learn: The Check Point analysis describes obfuscation layers (RC4 strings, control-flow flattening) that could inform behavioral detections, but the summary carries no IOCs or ATT&CK mappings to act on now — revisit when full indicator sets are published.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.