Beware of Malware infection in Facebook Ads Offering Cryptocurrency Rewards
Just because it’s a familiar tactic doesn’t mean you can let your guard down. A similar attack method using cryptocurrency rewards as bait has recently been identified again. This time, a case was confirmed in which the Node.Js-based malware JSCEAL was distributed through Facebook ads impersonating a cryptocurrency exchange. The threat actors lured users to a site designed to resemble a real exchange, then sent different installation files depending on the operating system to execute the malware. Over the past two months, JSCEAL infections have been confirmed on approximately 1,500 PCs in Korea, with both Windows and macOS systems included as Attack Targets. Let’s take a look at how JSCEAL deceives users, from the moment they click an ad to the malware code execution.
The Process of Installing the JSCEAL Malware
JSCEAL is malware that operates using the Node.Js environment. Threat actors entice users to click by advertising that installing the official program of a cryptocurrency exchange will result in rewards such as cryptocurrency. This malware attack is not limited to a specific time frame but has continued to target users in Korea up until recently.

[Figure 1] Status of JSCEAL Infections in Korea (August–September 2026)

[Figure 2] Facebook Ad Impersonating a Cryptocurrency Exchange
When a user clicks on the ad, they are redirected to a site that is disguised as a cryptocurrency exchange. The fake site mimics the exchange’s logo and color scheme and even displays real-time cryptocurrency price information, making it appear to be the official site.

[Figure 3] Comparison of the fake cryptocurrency exchange site and the legitimate site
However, behind the scenes, the page collects information about the user’s browser environment and the ad campaign, and checks the operating system. Malicious JavaScript embedded in the page identifies the operating system of the user’s device, retrieves configuration information from a server, and generates installation files tailored to each operating system. It creates a BAT file for Windows and a PKG configuration file for macOS to carry out subsequent malicious behavior.
The Entry Point for Malware on Windows is the BAT File
When a Windows user visits the disguised site, a BAT file that appears to be a legitimate installer is generated. The file name contains strings reminiscent of version numbers or installer names, making it easy for users to mistake it for a legitimate file.

[Figure 4] BAT Code
This BAT file acts as an initial loader, using PowerShell to download and execute additional code from an external source. It then modifies the system’s security settings and registers scheduled tasks, while also creating a desktop shortcut to make it appear as if a legitimate cryptocurrency exchange program has been installed.
The threat actor uses the scheduled tasks to ensure persistence. When a scheduled task runs, it adds an exclusion to Microsoft Defender to evade detection and communicates with the C2 server to receive additional commands.

[Figure 5] Binance shortcut file (legitimate)

[Figure 6] Code for registering a scheduled task
Subsequently, it was confirmed that the malware downloads an additional compressed file, decompresses its contents, and uses the embedded Node.Js runtime environment to execute the JSCEAL payload in the form of JavaScript or V8 bytecode. The initially downloaded BAT file is structured not as the final malware itself, but rather as a starting point for carrying out additional malicious activities.
Disguised as a PKG Installer on MacOS
On macOS, a different method is used. The disguised website combines settings and data received from the server to generate a PKG installer file within the browser. This file also uses a name reminiscent of version and release information to make it appear as a legitimate installation package.

[Figure 7] macOS PKG execution screen
When the user runs the PKG file, a script included in the installation process downloads and executes an additional shell script from an external server. Temporary files are deleted after execution to minimize traces.
The additional script displays a dialog box that is disguised to match the system language and prompts the user to enter their password. It was also confirmed that the script verifies whether the entered password matches the actual account credentials and then saves it to a separate file.

[Figure 8] Internal postinstall code in the PKG
In addition, it transmits system identification information, clipboard data, the computer name, and information related to the installation file to an external server. It then registers a LaunchAgent based on settings received from the server, creating an environment capable of performing follow-up command execution. Through this process, the threat actor can set up a Node.Js execution environment on macOS and execute additional JSCEAL payloads in JavaScript format.
JSCEAL Malware Response Guide
JSCEAL carries out malicious behavior in different ways on Windows and macOS. It is necessary to conduct an inspection focused on the key execution traces identified on each operating system and whether persistence has been established.
Windows Environment
-
Check for suspicious PowerShell execution history and evidence of additional code being downloaded and executed from external servers.
-
Check whether Microsoft Defender scan exclusions have been abnormally added or modified.
-
Check whether any suspicious scheduled tasks have been registered and review the execution details of any registered tasks.
-
Check for the presence of a desktop shortcut file (Users\Public\Desktop\Binance.LNK) created to appear as if a legitimate program (Binance) were installed.
-
Check for evidence of JavaScript or V8 bytecode code execution using Node.Js after downloading and decompressing additional compressed files.
MacOS Environment
-
Check for any traces of additional shell scripts being downloaded or executed during the installation process.
-
Check for any indications that the user was prompted to enter their password through a disguised dialog box.
-
Check for evidence that the entered password was verified and stored in a separate file.
-
Check for any evidence that the Machine ID, computer name, PKG file name, clipboard data, etc., Were transmitted externally.
-
Check whether any automatic startup items using LaunchAgent were registered abnormally.
-
Check for any evidence that additional JavaScript-based payloads were executed after the Node.Js runtime environment was set up.
Cryptocurrency exchange programs must be downloaded directly through the official website; do not run BAT or PKG installation files from unknown sources. If an unexpected password prompt appears during the installation process, it is safest to stop the installation and verify the source first.