news.mlab.sh
Back to the feed
threat-intel

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

High
Summary

Threat actors are leveraging the trusted Node.js runtime to deploy malicious payloads in a multi-pronged attack campaign targeting various industries. They are utilizing a combination of living-off-the-land tools, including Node.js versions of malware like AsukaStealer and EtherRAT, alongside social engineering techniques like ClickFix to gain initial access and establish persistent control. The campaign has been active since February 2026 and involves a sophisticated use of blockchain technology to bypass traditional C2 blocking measures.

Threat actors are increasingly utilizing the Node.js JavaScript runtime as a delivery mechanism for malicious payloads in a sustained attack campaign. According to a report from Symantec Threat Hunter Team, this tactic has been employed against government departments, technology companies, hotels, and other organizations since February 2026. The attackers are exploiting the legitimate, signed Node.exe binary to deploy malicious code, utilizing a registry Run key entry to relaunch payloads at every login.

One notable intrusion, targeting an Asian technology company between March 23 and July 25, 2026, involved deploying a malicious implant using Node.js to establish long-term access and retrieve commands via a technique called EtherHiding. The attackers initially gained access through the ClickFix social engineering technique, and later deployed C2Looper, a Rust-based backdoor documented by Zscaler ThreatLabz.

Alongside these tools, the attackers have utilized ModeloRAT and Mistic (aka MLTBackdoor), both associated with an initial access broker named KongTuke (aka Woodgnat). The campaign has been characterized by the abuse of “node.exe” to execute attacker JavaScript and chain PowerShell and Windows command-line tools, alongside a malicious Chrome extension named NexShield. A .NET payload, GateKeeper, featuring layered encryption and victim-fingerprinting logic, has also been deployed.

Recent activity against a U.S. fintech organization saw the deployment of C2Looper two months after initial access, with no evidence of credential theft or destructive operations. The attackers are utilizing a combination of living-off-the-land and dual-use tools, alongside commodity malware, and new tools such as Backdoor.Mistic, C2Looper, and the new version of AsukaStealer. The campaign is two-pronged, targeting both legitimate businesses through injected ClickFix lures and unsuspecting users who land on those sites.

To bypass traditional C2 blocking, attackers are leveraging the Polygon cryptocurrency blockchain as a dynamically updatable address book, allowing for ad hoc adjustment of C2 details at scale. Blocking a singular domain or IP address alone does not permanently sever attacker access.

To combat this threat, organizations are recommended to continuously audit public-facing websites for suspicious changes or malicious scripts, restrict unapproved browser extensions, and introduce security awareness training to help employees recognize ClickFix-style social engineering tactics.

Read the full article at The Hacker News