Attackers Revive Node.js Abuse to Run Malware and Maintain Persistence

· Original article ↗

Summary

Symantec reports that multiple threat actors have used the legitimate Node.js runtime in attacks since February 2026, including intrusions involving PowerShell, ransomware-linked malware and an implant that contacted Ethereum gateways.

Key points

  • Multiple actors have used Node.js in attacks since February 2026 against victims including government departments, technology companies and hotels; some activity is linked to ransomware.
  • Attackers abuse the legitimate, signed node.exe runtime to execute malicious scripts, which may evade signature-based detection; registry Run keys can relaunch payloads at login.
  • In an Asian technology-company intrusion, ClickFix-style access led to PowerShell activity and a Node.js implant that persisted for months and contacted Ethereum RPC gateways, likely using EtherHiding to retrieve commands or payloads.
  • Attackers also targeted a U.S. fintech company using a similar ClickFix and PowerShell chain, deploying the Rust-based C2Looper backdoor. Researchers found no evidence of credential theft, lateral movement or destructive activity in that intrusion.
  • Some attacks involved ModeloRAT, associated with initial access broker Woodgnat (also known as KongTuke), which has been linked publicly to intrusions involving multiple ransomware families.
  • Earlier Node.js attacks also used tools including AsukaStealer, which can steal credentials, session data and cryptocurrency wallet information, and EtherRAT, which uses blockchain-based command-and-control.

Article Details

Attack Vectors
  • In the two detailed intrusions, commands consistent with ClickFix-style lures were executed on victim hosts. The lure page or message in the U.S. intrusion was not recovered.
  • Attackers used PowerShell downloaders and attempted to deploy AdaptixC2 agents and Cobalt Strike Beacon. Several attempted payloads on the Asian technology company's host were blocked.
  • At the Asian technology company, attackers installed the official Node.js runtime and used node.exe to execute an implant. A current-user Run key entry was configured to relaunch it at login.
  • The Node.js implant contacted Ethereum blockchain RPC gateways, most likely to retrieve C&C configuration or additional payloads from a smart contract. It later contacted a Cloudflare Workers hostname that researchers assessed was likely being abused for C&C.
  • In the U.S. fintech intrusion, a PowerShell script appeared to be launched as a service and generated near-daily connections to attacker infrastructure. The attackers later deployed a Rust-based backdoor.
Defensive Notes
  • The article directs readers to the Symantec Protection Bulletin for the latest protection updates.
  • The reported intrusions illustrate that a legitimate, signed Node.js runtime can execute malicious scripts and be relaunched through a registry Run key.
  • No credential theft, lateral movement, or destructive payload was observed in the U.S. fintech intrusion; the attackers' objectives beyond maintaining a foothold remain unclear.

Indicators of compromise

TypeIndicatorContext
DOMAINauthorized-logins[.]netDomain listed as a network indicator of compromise.
DOMAINb6w9m2z5x8q1v3k[.]topDomain listed as a network indicator of compromise.
DOMAINbestopebel[.]plDomain listed as a network indicator of compromise.
DOMAINbookphotohot[.]proDomain listed as a network indicator of compromise.
DOMAINbookphotoreserv[.]proDomain listed as a network indicator of compromise.
DOMAINcarrolc[.]comDomain listed as a network indicator of compromise.
DOMAINchallenge-refernow[.]comDomain listed as a network indicator of compromise.
DOMAINcj06y9v4xab[.]comDomain listed as a network indicator of compromise.
DOMAINcsa-humanchecknow[.]comDomain listed as a network indicator of compromise.
DOMAINcwrtwright[.]comDomain listed as a network indicator of compromise.
DOMAINdatalayerservice[.]comDomain whose subdomains were reportedly configured as Cobalt Strike Beacon C&C.
DOMAINdrivefeedback[.]comDomain listed as a network indicator of compromise.
DOMAINgrande-luna[.]topDomain listed as a network indicator of compromise.
DOMAINhelthfulcore[.]infoDomain listed as a network indicator of compromise.
DOMAINhuman-check[.]topDomain listed as a network indicator of compromise.
DOMAINjoincroud[.]infoDomain listed as a network indicator of compromise.
DOMAINjokesprite[.]infoDomain listed as a network indicator of compromise.
DOMAINjusthandsoff[.]infoDomain listed as a network indicator of compromise.
DOMAINkedvs4wiykc[.]comDomain listed as a network indicator of compromise.
DOMAINkiptownim[.]infoDomain listed as a network indicator of compromise.
DOMAINklassniylink124[.]comDomain listed as a network indicator of compromise.
DOMAINlegaar[.]comDomain listed as a network indicator of compromise.
DOMAINministrew[.]infoDomain listed as a network indicator of compromise.
DOMAINmueleer[.]comDomain listed as a network indicator of compromise.
DOMAINninetyorigins[.]comDomain listed as a network indicator of compromise.
DOMAINnotstorageapis[.]comDomain listed as a network indicator of compromise.
DOMAINoeannon[.]comDomain listed as a network indicator of compromise.
DOMAINpartner-conflrmpanel[.]comDomain listed as a network indicator of compromise.
DOMAINperiod-checkavaldx[.]comDomain listed as a network indicator of compromise.
DOMAINphotbookguest[.]proDomain listed as a network indicator of compromise.
DOMAINrebronzeal[.]comDomain used for recurring PowerShell beaconing.
DOMAINrecepyman[.]infoDomain listed as a network indicator of compromise.
DOMAINrotoa-upda-lo[.]comDomain listed as a network indicator of compromise.
DOMAINrs2y15sungu[.]comDomain listed as a network indicator of compromise.
DOMAINsafedocphoto[.]infoDomain listed as a network indicator of compromise.
DOMAINsimsracing[.]netDomain listed as a network indicator of compromise.
DOMAINsql-updater-service[.]comDomain listed as a network indicator of compromise.
DOMAINstrapness[.]comAttacker-used domain from which an obfuscated PowerShell command fetched and ran a script.
DOMAINsummonhood[.]comAttacker-used domain contacted by the initial PowerShell command.
DOMAINthomphon[.]comDomain separately listed as a network indicator of compromise; an installer URL on it is also listed.
DOMAINtoogwido[.]sa[.]comDomain separately listed as a network indicator of compromise; a PowerShell-script URL on it is also listed.
DOMAINupd-domain-goloro[.]comDomain listed as a network indicator of compromise.
DOMAINupdater-worelos[.]comDomain listed as a network indicator of compromise.
DOMAINupscale-kolo[.]comDomain listed as a network indicator of compromise.
DOMAINvisa-safedocs[.]infoDomain listed as a network indicator of compromise.
DOMAINw3xasv14culvnqj[.]topDomain listed as a network indicator of compromise.
HOSTNAMEapi[.]datalayerservice[.]comHostname listed as a network indicator of compromise on the reported C&C domain.
HOSTNAMEapi[.]technodatabase[.]netHostname identified as C&C in the network indicators.
HOSTNAMEchat[.]devminelimited[.]comHostname listed as a network indicator of compromise.
HOSTNAMEchat[.]doctecsolutions[.]comHostname identified as C&C in the network indicators.
HOSTNAMEdefs[.]updater-worelos[.]comHostname listed as a network indicator of compromise.
HOSTNAMEdesign[.]devminelimited[.]comHostname identified as C&C in the network indicators.
HOSTNAMEdocs[.]datalayerservice[.]comHostname listed as a network indicator of compromise on the reported C&C domain.
HOSTNAMEformulario[.]puentelargo[.]orgHostname listed as a network indicator of compromise.
HOSTNAMEftps[.]upd-domain-goloro[.]comHostname listed as a network indicator of compromise.
HOSTNAMEmail[.]authorized-logins[.]netHostname listed as a network indicator of compromise.
HOSTNAMEmailes[.]upd-domain-goloro[.]comHostname listed as a network indicator of compromise.
HOSTNAMEmails[.]updater-worelos[.]comHostname listed as a network indicator of compromise.
HOSTNAMEmicrosoft[.]desereyunton[.]workers[.]devSpecific Cloudflare Workers hostname contacted by the implant and assessed as likely attacker-abused C&C.
HOSTNAMEnano[.]upscale-kolo[.]comHostname listed as a network indicator of compromise.
HOSTNAMEphp[.]authorized-logins[.]netHostname listed as a network indicator of compromise.
HOSTNAMEplanner[.]devminelimited[.]comHostname identified as C&C in the network indicators.
HOSTNAMEresources[.]datalayerservice[.]comHostname listed as a network indicator of compromise on the reported C&C domain.
HOSTNAMEsrv[.]doctecsolutions[.]comHostname listed as a network indicator of compromise.
HOSTNAMEsss[.]authorized-logins[.]netHostname listed as a network indicator of compromise.
HOSTNAMEupdate[.]update-fall[.]comHostname listed as a network indicator of compromise.
HOSTNAMEvideo[.]technodatabase[.]netHostname identified as C&C in the network indicators.
IPV4142[.]93[.]242[.]144Address listed as a network indicator of compromise.
IPV4144[.]31[.]53[.]78Address listed as a network indicator of compromise.
IPV4178[.]16[.]55[.]232Later backing infrastructure for PowerShell beaconing to rebronzeal[.]com.
IPV4185[.]205[.]211[.]217Earlier backing infrastructure for PowerShell beaconing to rebronzeal[.]com.
IPV4198[.]13[.]159[.]44Address listed as a network indicator of compromise.
IPV4199[.]91[.]221[.]42Address listed as a network indicator of compromise.
IPV445[.]158[.]196[.]23C2Looper C&C address; the article specifies port 8888.
SHA25608ea6bcce44b13813b321599b1ec88bb2c61314106286eca60402f7e738f3c4dListed indicator for agentdiags.exe, identified as an AdaptixC2 agent and suspicious file.
SHA256164cad33a0b076a6d01263e159ad06d2e7b1e9e1ace43294c252b11699022485Native Node.js addon evasion.node used by the implant.
SHA2561a8739e2dedebc971743dd0c985526f2373f871f9c31c5b2258a5e8b373e4df2AsukaStealer file indicator.
SHA2561d09357b6a096fdc35cd5c873eed15665d6b3c879d20c8cf01e6bca0005512cfBackdoor.Mistic file indicator.
SHA2561e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984Backdoor.Mistic loader file indicator.
SHA2561fc515870c681bf3e1b7947e2248bbcfe9918db2978117e91134de20bd42fd6aBackdoor.Mistic file indicator.
SHA256210615866cd2923cc0840f196eb12c00feee113e43850376803c8e024f7e63ceFile listed as suspicious in the indicators section.
SHA256232b5115f4b78fe01c6497b1039b85ee57f6a58abd095dc80ea4d3c5e6cef6d6File listed as suspicious in the indicators section.
SHA25624d71cb6cf6d34871031564c3f104195b812f8e72ceffb1f0ce1936998531e6fPowerShell script accumulatally.ps1 used in the intrusion.
SHA2562cd88d5280a61714836f5f07a16df190911c5b952af2998dbbcda910b3b1c494Backdoor.Mistic file indicator.
SHA25634d798a6c55e57ed0932b6499f4fbcb5454bdfca903307be101a0594b0ac07bcFake lock screen file indicator.
SHA256374d7008d9ba33b440d1838561f59d936a25092e4dc60def6346a9486a799906Bootstrap download-script file indicator.
SHA2563f797a639bc855bc6d5471f327924b62d10900ddec49b970eca6604142bbb4beBackdoor.Mistic file indicator.
SHA256466762502123d91be56d9c5a3b92a55c7e3a8c8939a3006cfaee565440ffe5e4Listed indicator for cobol64.exe, identified as an AdaptixC2 agent.
SHA25659358233a269ce587a1b24ca35e79ab294ce560b43555b500d02cf03687c4fcfCobalt Strike Beacon identified as thread_indirect.exe.
SHA25659e3c4cb06331b4f2d78a9a0592f3747e573bd01c5a7650c26361d1e25520712Backdoor.Mistic file indicator.
SHA2565a27de542f8e4f5f9020baea00ff9e92a5d9a76e3c5143bcfccb55a4ab0be351Listed indicator for thread.exe, identified as Cobalt Strike Beacon.
SHA25672db2ea09c8d4e09ef99e1342b42491a6aebf6008a1e5337131c8bde06b2ea22File listed as suspicious in the indicators section.
SHA2567d4fb94f6b4623690daea67ed52e97705cb102f443988ff605f2a9c4898244dcBackdoor.Mistic file indicator.
SHA2567f0754c3c3146efb451ac8e80ef6c3d61395e7974485b94e20ce436341a41240Bootstrap download-script file indicator.
SHA2568238fa99927aea6a6837792e5c8122ecd9458dd1164a8fd6c86da6794278bcefAdaptixC2 agent identified as age.exe.
SHA25683e970feb3f10692c164f6889f7a026f135c2433e5bf8e662a6e63a3b81267b7File listed as suspicious in the indicators section.
SHA2568c935feec4bd05d5d918df308be417532fb42608fb989a08eab183e0ae699235File listed as suspicious in the indicators section.
SHA2569e52cc90cff150abe21f0a6440e86e0a99ff383b81061b96def8948e21d0ac66Backdoor.Mistic file indicator.
SHA256a98dde0e43267e973bd88cb630791cb0b667b8a2e788dc47adf2e85e813eea86File listed as suspicious in the indicators section.
SHA256afd5f1ed45a9867daf3bc64152cef460a06b164c8183e490db39146d4749a82cBackdoor.Mistic file indicator.
SHA256b0f918666bb11e8f25956cdfe240bc26b4bd3192f93c123a056fe3df6801a5f5File listed as suspicious in the indicators section.
SHA256b2fe498de7a56646df1a00db3513a6c31eb660fa0405c00cdd2219f26c29ca23File listed as suspicious in the indicators section.
SHA256bdd376d48d5ed482ed48e93ae80579b7c089a3c854225b97cf5f2291ebdb476bEtherRAT file indicator.
SHA256c854382d457eddbae9887350f9f19a2bc35c02968900b8f534503d0dcbd824a5Rust-based backdoor identified as xhelper64.exe.
SHA256cd211247d1c1c1ca4d77418fea60efafd0736017ef35c9191aed85c684adc153Suspicious file identified as agent_startup.exe.
SHA256ced6b0f44410f6133ad63b61e04613a8b56cc3338d7b34497540e9541163e7ecBackdoor.Mistic file indicator.
SHA256d2705499d24772fa25049f6a58d873a2ff6607d01c64622e85977e7d17d5df41Backdoor.Mistic file indicator.
SHA256d2c60d76e65f547baa13f156470b10f8059082be5603a6e04dd75315043c0a50File listed as suspicious in the indicators section.
SHA256d2c637235d62ad766f961f9b8563f6a0e6db2ec0a343470385991b4df826afbcBackdoor.Mistic file indicator.
SHA256d3e64a86909201f930c35b0f1e93e7a2c40a680e951d1fbb78b3047b8cb5c780File listed as suspicious in the indicators section.
SHA256d965de63dbd27abb00efeb9bea029cd38952dc5c268b61a522b2358d8452e43aListed indicator for main.x64a.exe; identified as an AdaptixC2 agent.
SHA256db972979d508e75fe730d3b72c2701470fbdaeaf8ebdd674744754fa44438ca5Backdoor.Mistic file indicator.
SHA256e237801a9ef693d0d4c7d148965bb50c90946b43b8b9e00aa5e39fe5393a26e9PowerShell script earthquakeist.ps1 used in the intrusion.
SHA256e901df53873d5379ad9399c63d3e014c7be188a7599b32e5b36b1de1cf7d5fbaAdaptixC2 agent identified as age64.exe.
SHA256ebadfe4f370b6129402df7107581c7142c916aa7b0fae588540ab16beb5c4caeBackdoor.Mistic file indicator.
SHA256f591275a8f014b29e567529d67c54eb7bb4473db1c38737d6bfd5b3d52c9344eBackdoor.Mistic file indicator.
SHA256fb3630822b70bacb56aa4cec29b5a0e3e9acb3920809e70310a4003385a6d34aBackdoor.Mistic file indicator.
URLhxxp[:]//178[.]16[.]54[.]253/~extranet/phot7482[.]exeExecutable URL listed as a network indicator of compromise.
URLhxxp[:]//178[.]16[.]54[.]253/~extranet/Tmsyz[.]exeExecutable URL listed as a network indicator of compromise.
URLhxxp[:]//193[.]58[.]122[.]42/files/hvnc2[.]exeExecutable URL listed as a network indicator of compromise.
URLhxxp[:]//193[.]58[.]122[.]42/files/rat[.]exeExecutable URL listed as a network indicator of compromise.
URLhxxp[:]//193[.]58[.]122[.]42/files/rat1[.]exeExecutable URL listed as a network indicator of compromise.
URLhxxp[:]//193[.]58[.]122[.]42/files/stil[.]exeExecutable URL listed as a network indicator of compromise.
URLhxxp[:]//193[.]58[.]122[.]42/files/stil1[.]exeExecutable URL listed as a network indicator of compromise.
URLhxxp[:]//199[.]231[.]70[.]175:443/update[.]aspxLikely staging-server URL contacted during an attempted AdaptixC2 agent download.
URLhxxp[:]//94[.]156[.]114[.]250/files/lasttry[.]exeExecutable URL listed as a network indicator of compromise.
URLhxxp[:]//thomphon[.]com/update[.]msiInstaller URL listed as a network indicator of compromise.
URLhxxps[:]//rebronzeal[.]comEndpoint contacted repeatedly by the intrusion's PowerShell script.
URLhxxps[:]//summonhood[.]comAttacker-used endpoint contacted at the start of the U.S. fintech intrusion.
URLhxxps[:]//toogwido[.]sa[.]com/Ca[.]ps1PowerShell-script URL listed as a network indicator of compromise.
URLhxxps[:]//www[.]xt24[.]com/install/update[.]ps1PowerShell-script URL listed as a network indicator of compromise.

MITRE ATT&CK

Threat Actors

Malware

8Baselinked to attacks involving multiple ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.Akirapublicly linked to attacks involving multiple ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.AsukaStealerAsukaStealer: Node.js version of AsukaStealer, which had not been seen before. Malware-as-a-service (MaaS) that can be used to steal credentials, session data, cookies, and cryptocurrency wallet information, as well asBackdoor.MisticNode.js was also used in a recent attack that the Symantec Threat Hunter Team blogged about, in which a new backdoor called Backdoor.Mistic was deployed. This backdoor may also be developed by Woodgnat. Black Bastato attacks involving multiple ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.C2LooperThe same attackers also compromised a U.S. fintech company, deploying a Rust-based backdoor known as C2Looper, which has been linked to ransomware attacks.Embargomultiple ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.EtherRATEtherRAT: Stealthy Remote Access Trojan (RAT) that is written in Node.js and is largely known for its use of "EtherHiding," a technique that conceals and updates its Command-and-Control (C&C) server addresses by hidingInterlockwhich has been publicly linked to attacks involving multiple ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.LooperC2On July 16, attackers deployed a Rust-based backdoor (LooperC2), indicating the victim was likely of interest enough to carry out additional post-compromise activity. However, no evidence of credential theft, lateralModeloRATSome of the attacks involved ModeloRAT, believed to be developed by an initial access broker called Woodgnat (aka KongTuke), which has been publicly linked to attacks involving multiple ransomware families, includingQilinKongTuke), which has been publicly linked to attacks involving multiple ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.Rhysidahas been publicly linked to attacks involving multiple ransomware families, including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo.

Vendors

Products

Tools

Countries

Industries

Related Articles