WEEVILPROXY is a threat cluster associated with JSCeal malvertising activity targeting cryptocurrency traders and investors. The activity uses malicious search and social-media advertisements and counterfeit cryptocurrency-trading websites to distribute fraudulent trading-software installers. JSCeal is compiled V8 JavaScript malware that enumerates Chromium-based browsers and steals stored credentials, cookies, OAuth tokens, and other browser data. It can replay stolen browser sessions to bypass authentication to victims’ online accounts, record keystrokes, capture screenshots, and operate a local interception proxy capable of modifying selected cryptocurrency-service traffic. The malware employs layered JavaScript obfuscation and compiled bytecode to hinder analysis. WEEVILPROXY activity has been assessed as overlapping with the MeadowLocust cluster; related SourTrade malvertising activity also overlaps with JSCeal campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducts cryptocurrency-themed malvertising campaigns that impersonate trading brands and distribute JSCeal, a credential-stealing and surveillance malware capable of browser-session replay and traffic interception.
Operates malvertising campaigns that redirect victims to counterfeit cryptocurrency-trading websites and fake TradingView installers, deploying JSCeal for browser credential theft, surveillance, session replay, and cryptocurrency-focused traffic interception.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.