Netskope Threat Labs

BROWSER-OTHER JavaScript-based backdoor communication attempt

IPS-CFW

1 SID: 200318

Detects web content that opens a WebSocket channel and dispatches incoming messages to dynamic handlers, a pattern consistent with JavaScript-based backdoor communication. Malware operators use browser WebSocket channels to relay commands and exfiltrate data over ordinary web traffic that blends into normal browsing.

No cross-references or related blog posts found for this signature.