[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fntmVuOCFjZ2dwaiXe74u3PZXIGeWgw-jlg0qRTPbPdc":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"bba1dbe8-199f-4bf5-8302-2efa9eeb320f","Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks","attackers-turn-trusted-node-js-runtime-into-malware-delivery-tool-in-targeted-at-0ffead","Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. \"The technique's appeal is that node.exe (the","Threat actors are exploiting the legitimate Node.js JavaScript runtime, node.exe, to deploy malicious payloads in targeted attacks against government, technology, and hotel sectors since February 2026. This technique bypasses signature-based detection by embedding malicious code in interpreted scripts and using registry Run keys for persistence. The attackers have also been linked to the KongTuke (Woodgnat) initial access broker, employing tools like ModeloRAT, Mistic, and GateKeeper.","Attackers use Node.js runtime to deliver malware in targeted attacks.","Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks Ravie LakshmananSep 03, 2026Malware \u002F Web Security Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. \"The technique's appeal is that node.exe (the binary that runs Node.js) is a legitimate, signed developer tool,\" the Broadcom-owned cybersecurity division said in a report shared with The Hacker News. \"The attacker's malicious code lives in interpreted scripts rather than in a binary, making it less likely to trigger signature-based detection, while a registry Run key entry can relaunch the payload at every login.\" In one intrusion observed between March 23 and July 25, 2026, targeting an unspecified Asian technology company, attackers downloaded the official Node.js installer from nodejs[.]org and used the trusted, signed runtime to deploy a malicious implant to establish long-term access and retrieve commands or tooling using a technique called EtherHiding. The threat actors are said to have shifted to this approach after their repeated attempts to deploy AdaptixC2 and Cobalt Strike beacons on the victim's network were blocked after obtaining initial access through the ClickFix social engineering technique. Interestingly, the technique has also been employed alongside ModeloRAT and Mistic (aka MLTBackdoor), both of which are assessed to be the work of an initial access broker named KongTuke (aka Woodgnat). In June 2026, Symantec disclosed that Woodgnat attack chains are characterized by the abuse of \"node.exe\" to execute attacker JavaScript and chain PowerShell and Windows command-line tools, as well as a malicious Chrome extension named NexShield as part of a ClickFix variant dubbed CrashFix. Another tool put to use in these attacks is a .NET payload known as GateKeeper that features layered encryption and victim-fingerprinting logic. The same modus operandi has been observed against a U.S. fintech organization, with the attack paving the way for the deployment of C2Looper, a Rust-based backdoor documented by Zscaler ThreatLabz last month. The earliest observed activity occurred on May 6, 2026, when the attackers exploited the foothold gained via ClickFix to deploy an AdaptixC2 agent and a Cobalt Strike Beacon. It's worth noting that the installation of C2Looper took place more than two months after the initial events, although there is no evidence that the threat actors engaged in credential theft, lateral movement, or destructive operations. It's also unclear if they achieved their end goals beyond establishing the foothold using the backdoor. \"While the use of node.js and connection to the Ethereum blockchain wasn't observed in that incident, shared domains and similarities in the attack chain point to the same attackers being behind the activity,\" Symantec said. \"It's likely we didn't see Node.js activity on this organization because the attackers were able to successfully deploy a backdoor.\" The cybersecurity company said multiple threat actors are exploiting Node.js in attacks. Some of the tools used in these intrusions include a Node.js version of an information stealer named AsukaStealer, EtherRAT, and other legitimate Microsoft and command-line utilities. \"Attackers using Node.js appear happy to use a combination of both living-off-the-land and dual-use tools in their attacks, as well as commodity malware, and new tools such as Backdoor.Mistic, C2Looper, and the new version of AsukaStealer,\" Symantec concluded. \"This indicates that attackers with a variety of skill levels may be using Node.js as it has returned to popularity.\" The disclosure comes as GuidePoint Security said attackers have compromised at least 31 organizations, including e-commerce, professional services, and retail logistics businesses, through a ClickFix campaign that serves fake CAPTCHA verification prompts to visitors arriving at the compromised sites and deploys a persistent backdoor that abuses EtherHiding to locate its command-and-control (C2) infrastructure and receive commands. The campaign is two-pronged in that it yields two different victim types: the legitimate business whose website is injected to display the ClickFix lure and unsuspecting users who land on those sites. \"Traditionally, ClickFix malware can be neutralized by blocking the attacker's C2 server, cutting off communications with infected machines,\" GuidePoint Security researcher Jean-Pierre Mouton said. \"This campaign sidesteps that defense by using the Polygon cryptocurrency blockchain as a dynamically updatable address book.\" \"Because it allows for ad hoc adjustment of C2 details at scale, blocking a singular domain or IP address alone does not permanently sever attacker access. For fractions of a cent per transaction, the attacker can redirect every infected machine to a new C2 server automatically.\" Over the past two years, ClickFix and its numerous variants have taken off in a big way as they aim to trick users into performing undesirable actions under the pretext of fixing an error or proving they are not bots by copying a command presented in the lure and pasting it onto the Windows Run dialog or the Windows Terminal app, effectively compromising their own systems in the process. To combat the threat and others like it, organizations are recommended to audit public-facing websites continuously for suspicious changes or malicious scripts, restrict unapproved browser extensions, and introduce security awareness training to help employees recognize ClickFix-style social engineering tactics. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Blockchain Security, Malware, Social Engineering, Web Security ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Learn How to Build Security Operations Ready for AI-Powered Attacks Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Frontier AI: Vulnerability Management's Systemic Revolution Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals Why Threat Intelligence Needs OT Contex","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fattackers-turn-trusted-nodejs-runtime.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEixQdi-o7wSstsDvvGluX8EDCUhGUHwpKjSkMSaigZZkFOEI_mWS0kLYvjSaG9olG2Y8GYxqH2kKRUtT82RVMLfW-FuBdrWMbGSfJMVVK3YAL3FClWT6t0Dz33NzHEYK1dL93JLl7YzyETY1i9ZYpRty-BG5Vfk_vGUggKigBtpQZxKuUW8-Jg3m9xZV8BL\u002Fs1600\u002Fjsnode.jpg","2026-09-03T10:43:01+00:00","2026-09-03T12:00:16.540528+00:00",8,[18,21,23,25,27,29],{"name":19,"type":20},"Node.js","product",{"name":22,"type":20},"Cobalt Strike",{"name":24,"type":20},"AdaptixC2",{"name":26,"type":20},"ModeloRAT",{"name":28,"type":20},"Mistic",{"name":30,"type":31},"KongTuke","threat_actor","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":32,"icon":34,"name":35,"slug":36},null,"Malware","malware",[38,43,48,50],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":49},{"id":32,"icon":34,"name":35,"slug":36},{"category":51},{"id":52,"icon":34,"name":53,"slug":54},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[56],{"type":57,"value":58,"context":59},"domain","nodejs[.]org","Official Node.js installer download source."]