SECURITY·중요도 8·2026. 09. 07.·The Hacker News

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

── KO ──────────────────

JSCeal 악성코드는 세션 쿠키 도용으로 구글 인증을 우회할 수 있는 능력을 지닌다.

사이버 보안 연구자들이 JSCeal이라는 복잡한 악성코드를 분석했다. 이 악성코드는 자격증명 수집, 감시 및 트래픽 가로채기의 기능을 가지고 있으며, 구글 인증을 세션 쿠키를 도용하여 우회할 수 있다. Check Point Research는 이 악성코드가 RC4로 보호된 문자열, 제어 흐름 평탄화, 프록시 함수, 작업 래퍼 등 여러 기술을 사용한다고 밝혔다.


── EN ──────────────────

JSCeal malware can bypass Google authentication using stolen session cookies.

Cybersecurity researchers have analyzed a sophisticated malware named JSCeal. This malware is capable of credential harvesting, surveillance, and traffic interception, and can bypass Google authentication using stolen session cookies. According to Check Point Research, the payloads are protected using various techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers.

원문 보기 →목록으로