s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.weevilproxy

📛 Threat Title

Malware family: WEEVILPROXY

Category: WEEVILPROXY First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.weevilproxy`. Printable name: WEEVILPROXY. Aliases: JSCEAL.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain js.weevilproxy VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.weevilproxy

IOC database

Type
domain
Value
js.weevilproxy
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-js.weevilproxy

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.weevilproxy

References (1)

Remediations (10)

  • web:clickcontrol.com

    Cybersecurity experts have discovered a sophisticated malware campaign using fake Facebook ads to distribute JSCEAL malware through fraudulent cryptocurrency trading apps.

  • web:cyberpress.org

    This technique, borrowed from Pulsar RAT and WEEVILPROXY , highlights XWorm V6's emphasis on resilience. XWorm V6's combination of refined injection, robust plugin delivery, and layered persistence mechanisms underscores the evolving sophistication of RAT campaigns.

  • web:cyberwarriorsmiddleeast.com

    Rise of Fake Cryptocurrency Trading Apps: A Cybersecurity Concern Introduction to the Malware Threat Cybersecurity experts have raised alarms about a persistent campaign that distributes counterfeit cryptocurrency trading applications. This initiative is employing a malicious V8 JavaScript malware known as JSCEAL, capable of capturing sensitive information, including user credentials and ...

  • web:hackersonlineclub.com

    A new cyberattack campaign is actively leveraging Facebook advertisements to spread malicious cryptocurrency trading applications, ultimately deploying the potent JSCEAL malware . This campaign, first observed in March 2024 and tracked by cybersecurity firms like Microsoft and WithSecure (as WEEVILPROXY ), highlights a growing threat where social media platforms are exploited for advanced ...

  • web:labs.withsecure.com

    The malware campaign targets cryptocurrency users, a user base estimated to be in the hundreds of millions which has emerged as a viable and effective lure to infect users and organizations across all sectors alike. The campaign targets victims globally, with infections observed across each continent. Although the campaign targets cryptocurrency users, WithSecure has observed non ...

  • web:research.checkpoint.com

    This sophisticated piece of malware is designed to gain absolute control of the victim machine, while being resilient against conventional security tools. The combination of compiled code and heavy obfuscation, while displaying a wide variety of functionality, made analysis efforts challenging and time-consuming.

  • web:www.criticalstart.com

    Cisco has confirmed active exploitation of a critical stack overflow flaw (CVE-2025-20352) in the SNMP subsystem of its IOS and IOS XE software. Separately, a new campaign is using thousands of Facebook ads to distribute hybrid malware that steals from cryptocurrency wallets.

  • web:www.cxodigitalpulse.com

    Cybersecurity experts are warning about a sophisticated malware campaign that is distributing fake cryptocurrency trading applications to deploy a powerful JavaScript-based malware variant known as JSCEAL. This malware is capable of stealing sensitive user data, including login credentials, browser cookies, wallets, and even Telegram account details. According to a recent analysis by Check ...

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.resecurity.com

    Following the recent Twilio hack leading to the leakage of 2FA (OTP) codes, cybercriminals continue to upgrade their attack arsenal to orchestrate advanced phishing campaigns targeting users worldwide. Resecurity has recently identified a new Phishing-as-a-Service (PhaaS) called EvilProxy advertised in the Dark Web. On some sources the alternative name is Moloch, which has some connection to a ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.