Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Trump Taps Army Engineering Official as Acting Secretary

    September 4, 2026

    The unusually muted Tesla Cybercab launch

    September 4, 2026

    Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

    September 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Trump Taps Army Engineering Official as Acting Secretary
    • The unusually muted Tesla Cybercab launch
    • Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
    • Bitcoin-Gold Correlation Hits Six-Year High
    • Renewable energy in NI reaches record level
    • EU, NATO Punish Russia for an Alleged Drone Attack on Germany’s Leipzig Airport
    • Argentina to sanction oil firms as Falklands dispute with UK heats up
    • Wenn Ulrich Siegmund Ministerpräsident wird – POLITICO
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 4
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 4, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.

    According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.

    “The technique’s appeal is that node.exe (the binary that runs Node.js) is a legitimate, signed developer tool,” the Broadcom-owned cybersecurity division said in a report shared with The Hacker News. “The attacker’s malicious code lives in interpreted scripts rather than in a binary, making it less likely to trigger signature-based detection, while a registry Run key entry can relaunch the payload at every login.”

    In one intrusion observed between March 23 and July 25, 2026, targeting an unspecified Asian technology company, attackers downloaded the official Node.js installer from nodejs[.]org and used the trusted, signed runtime to deploy a malicious implant to establish long-term access and retrieve commands or tooling using a technique called EtherHiding.

    The threat actors are said to have shifted to this approach after their repeated attempts to deploy AdaptixC2 and Cobalt Strike beacons on the victim’s network were blocked after obtaining initial access through the ClickFix social engineering technique.

    Cybersecurity

    Interestingly, the technique has also been employed alongside ModeloRAT and Mistic (aka MLTBackdoor), both of which are assessed to be the work of an initial access broker named KongTuke (aka Woodgnat).

    In June 2026, Symantec disclosed that Woodgnat attack chains are characterized by the abuse of “node.exe” to execute attacker JavaScript and chain PowerShell and Windows command-line tools, as well as a malicious Chrome extension named NexShield as part of a ClickFix variant dubbed CrashFix. Another tool put to use in these attacks is a .NET payload known as GateKeeper that features layered encryption and victim-fingerprinting logic.

    The same modus operandi has been observed against a U.S. fintech organization, with the attack paving the way for the deployment of C2Looper, a Rust-based backdoor documented by Zscaler ThreatLabz last month. The earliest observed activity occurred on May 6, 2026, when the attackers exploited the foothold gained via ClickFix to deploy an AdaptixC2 agent and a Cobalt Strike Beacon.

    It’s worth noting that the installation of C2Looper took place more than two months after the initial events, although there is no evidence that the threat actors engaged in credential theft, lateral movement, or destructive operations. It’s also unclear if they achieved their end goals beyond establishing the foothold using the backdoor.

    “While the use of node.js and connection to the Ethereum blockchain wasn’t observed in that incident, shared domains and similarities in the attack chain point to the same attackers being behind the activity,” Symantec said. “It’s likely we didn’t see Node.js activity on this organization because the attackers were able to successfully deploy a backdoor.”

    The cybersecurity company said multiple threat actors are exploiting Node.js in attacks. Some of the tools used in these intrusions include a Node.js version of an information stealer named AsukaStealer, EtherRAT, and other legitimate Microsoft and command-line utilities.

    “Attackers using Node.js appear happy to use a combination of both living-off-the-land and dual-use tools in their attacks, as well as commodity malware, and new tools such as Backdoor.Mistic, C2Looper, and the new version of AsukaStealer,” Symantec concluded. “This indicates that attackers with a variety of skill levels may be using Node.js as it has returned to popularity.”

    The disclosure comes as GuidePoint Security said attackers have compromised at least 31 organizations, including e-commerce, professional services, and retail logistics businesses, through a ClickFix campaign that serves fake CAPTCHA verification prompts to visitors arriving at the compromised sites and deploys a persistent backdoor that abuses EtherHiding to locate its command-and-control (C2) infrastructure and receive commands.

    Cybersecurity

    The campaign is two-pronged in that it yields two different victim types: the legitimate business whose website is injected to display the ClickFix lure and unsuspecting users who land on those sites.

    “Traditionally, ClickFix malware can be neutralized by blocking the attacker’s C2 server, cutting off communications with infected machines,” GuidePoint Security researcher Jean-Pierre Mouton said. “This campaign sidesteps that defense by using the Polygon cryptocurrency blockchain as a dynamically updatable address book.”

    “Because it allows for ad hoc adjustment of C2 details at scale, blocking a singular domain or IP address alone does not permanently sever attacker access. For fractions of a cent per transaction, the attacker can redirect every infected machine to a new C2 server automatically.”

    Over the past two years, ClickFix and its numerous variants have taken off in a big way as they aim to trick users into performing undesirable actions under the pretext of fixing an error or proving they are not bots by copying a command presented in the lure and pasting it onto the Windows Run dialog or the Windows Terminal app, effectively compromising their own systems in the process.

    To combat the threat and others like it, organizations are recommended to audit public-facing websites continuously for suspicious changes or malicious scripts, restrict unapproved browser extensions, and introduce security awareness training to help employees recognize ClickFix-style social engineering tactics.

    Attackers attacks Delivery Malware Node.js runtime targeted tool trusted Turn
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million

    Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

    Your Employee’s Password Appeared in an Infostealer Log. Now What?

    BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

    Critical Elementor Pro flaw exploited to take over WordPress sites

    French hospital fined €500,000 after breach exposes data of 727,000

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Trump Taps Army Engineering Official as Acting Secretary

    September 4, 2026

    The unusually muted Tesla Cybercab launch

    September 4, 2026

    Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

    September 4, 2026

    Bitcoin-Gold Correlation Hits Six-Year High

    September 4, 2026
    Latest Posts

    Ultrafast X-rays capture chemistry unfolding atom by atom

    July 31, 2026

    How a PPE company’s highly publicized $32M Bitcoin strategy quietly expired without purchasing a single coin

    July 31, 2026

    Critical Flaw Led to Azure Cosmos DB Pwnage

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Trump Taps Army Engineering Official as Acting Secretary

    September 4, 2026

    The unusually muted Tesla Cybercab launch

    September 4, 2026

    Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

    September 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.