WEEVILPROXY
Aliases: JSCEAL
- First seen
- 2023-01-15 00:00:00
- Malware type
- credential-stealer, spyware, trojan
- Profile updated
- 2026-07-07 14:34:58
Targeted industries: technology-and-telecommunications financial-services government-and-public-sector
Context
WEEVILPROXY is a sophisticated and featureful stealer which has a payload primarily written in NodeJS. The developer has put in concerted effort to develop the malware’s breadth of capabilities, including novel techniques not observed in any prior malware campaigns - to our knowledge. These new TTPs include methods to modify Windows Setup and Windows Recovery to enable long-term persistence, as well as methods to patch browser extensions ‘on the fly’.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Js.Weevilproxy (report)
- labs.withsecure.com — Weevilproxy (report)