TF-MAL-js.weevilproxy
📛 Threat Title
Malware family: WEEVILPROXY
Description
ThreatFox malware family `js.weevilproxy`. Printable name: WEEVILPROXY. Aliases: JSCEAL.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.weevilproxy
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.weevilproxy
IOC database
- Type
- domain
- Value
js.weevilproxy- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.weevilproxy
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.weevilproxy
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:clickcontrol.com
Cybersecurity experts have discovered a sophisticated malware campaign using fake Facebook ads to distribute JSCEAL malware through fraudulent cryptocurrency trading apps.
-
web:cyberpress.org
This technique, borrowed from Pulsar RAT and WEEVILPROXY , highlights XWorm V6's emphasis on resilience. XWorm V6's combination of refined injection, robust plugin delivery, and layered persistence mechanisms underscores the evolving sophistication of RAT campaigns.
-
web:cyberwarriorsmiddleeast.com
Rise of Fake Cryptocurrency Trading Apps: A Cybersecurity Concern Introduction to the Malware Threat Cybersecurity experts have raised alarms about a persistent campaign that distributes counterfeit cryptocurrency trading applications. This initiative is employing a malicious V8 JavaScript malware known as JSCEAL, capable of capturing sensitive information, including user credentials and ...
-
web:hackersonlineclub.com
A new cyberattack campaign is actively leveraging Facebook advertisements to spread malicious cryptocurrency trading applications, ultimately deploying the potent JSCEAL malware . This campaign, first observed in March 2024 and tracked by cybersecurity firms like Microsoft and WithSecure (as WEEVILPROXY ), highlights a growing threat where social media platforms are exploited for advanced ...
-
web:labs.withsecure.com
The malware campaign targets cryptocurrency users, a user base estimated to be in the hundreds of millions which has emerged as a viable and effective lure to infect users and organizations across all sectors alike. The campaign targets victims globally, with infections observed across each continent. Although the campaign targets cryptocurrency users, WithSecure has observed non ...
-
web:research.checkpoint.com
This sophisticated piece of malware is designed to gain absolute control of the victim machine, while being resilient against conventional security tools. The combination of compiled code and heavy obfuscation, while displaying a wide variety of functionality, made analysis efforts challenging and time-consuming.
-
web:www.criticalstart.com
Cisco has confirmed active exploitation of a critical stack overflow flaw (CVE-2025-20352) in the SNMP subsystem of its IOS and IOS XE software. Separately, a new campaign is using thousands of Facebook ads to distribute hybrid malware that steals from cryptocurrency wallets.
-
web:www.cxodigitalpulse.com
Cybersecurity experts are warning about a sophisticated malware campaign that is distributing fake cryptocurrency trading applications to deploy a powerful JavaScript-based malware variant known as JSCEAL. This malware is capable of stealing sensitive user data, including login credentials, browser cookies, wallets, and even Telegram account details. According to a recent analysis by Check ...
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.resecurity.com
Following the recent Twilio hack leading to the leakage of 2FA (OTP) codes, cybercriminals continue to upgrade their attack arsenal to orchestrate advanced phishing campaigns targeting users worldwide. Resecurity has recently identified a new Phishing-as-a-Service (PhaaS) called EvilProxy advertised in the Dark Web. On some sources the alternative name is Moloch, which has some connection to a ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.