Millions of cryptocurrency users are at risk as a new malware campaign uses malicious ads to trick them into downloading fake trading apps. According to Check Point Research (CPR), the attack—known as JSCEAL—has already reached millions of potential victims in the EU and beyond.
The malware campaign began in March 2024 and is still active in mid-2025. Researchers estimate over 35,000 fake ads have appeared online, impersonating nearly 50 popular crypto platforms.
How JSCEAL Works
JSCEAL relies on clever filtering to ensure only select targets are affected. When a victim clicks a malicious ad, the system checks their IP address and referral source. If the criteria match—often targeting users who come from Facebook—the victim is sent to a convincing fake website.
Once there, the fake site prompts the user to download a malicious app. To avoid raising suspicion, the installer opens the real version of the crypto site in a browser window using msedge_proxy.exe. Meanwhile, the actual malware steals the user’s wallet and login data in the background.
Why It’s So Dangerous
What makes this malicious ads campaign especially effective is its stealth. JSCEAL uses JavaScriptCore (JSC)-based payloads that evade traditional antivirus detection. CPR reports that even hundreds of submitted samples went unnoticed on VirusTotal for a long time.
The malware has evolved with anti-analysis techniques and selective delivery methods, which help it avoid exposure and remain undetected. Some campaigns don’t even deliver the final malware payload if a user doesn’t meet their targeting requirements.
A Widening Threat
Though the campaign started in the EU, CPR warns that JSCEAL is spreading to other regions. The total number of global exposures could easily exceed 10 million users.
Researchers say that despite the stealthy approach, JSCEAL remains dependent on legitimate frameworks that security systems can still monitor. As a result, cybersecurity solutions may eventually catch up—but for now, the threat remains active and widespread.
Conclusion
The malicious ads campaign targeting crypto users reveals how sophisticated threat actors have become. By combining ad fraud, fake apps, and stealthy malware, the JSCEAL campaign poses a serious risk to anyone trading digital assets. Staying alert, avoiding suspicious ads, and using strong cybersecurity tools is more important than ever.


0 responses to “Malicious Ads Target Crypto Users”