Hackers Turn Trusted Node.js Runtime Into Malware Launcher in Ransomware-Linked Attacks
ID: bc168b35-3166-5a0f-9edf-e4954d276494
STIX ID: report--bc168b35-3166-5a0f-9edf-e4954d276494
Feed Name: cybersecurityNews.com
Symantec Threat Hunter Team observed multiple threat actors since February 2026 abusing the legitimate, signed Node.js runtime to run malicious JavaScript and evade detection across government, technology, and hotel targets in Asia and the United States; attackers used persistence via Windows Run registry keys and techniques like EtherHiding (storing commands/payloads in Ethereum smart contracts) and deployed tools including AdaptixC2, Cobalt Strike, C2Looper, ModeloRAT, AsukaStealer and EtherRAT. The report links some intrusions to an initial access broker (Woodgnat/KongTuke) tied to several ransomware families and recommends monitoring for unexpected Node.js installations, unusual Run-key entries, and outbound traffic to blockchain RPC endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
