Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays
ID: d75eb14b-53d6-5c38-9582-48321090976a
STIX ID: report--d75eb14b-53d6-5c38-9582-48321090976a
Feed Name: cybersecurityNews.com
RoadK1ll is a lean, Node.js-based reverse-tunneling implant that creates an outbound WebSocket tunnel to attacker infrastructure, turning infected machines into stealthy relays for reaching internal systems. The report details a custom 5-byte-framed WebSocket protocol with multiple channel support, message types for DATA/CONNECT/CONNECTED/CLOSE/ERROR, persistence and reconnection behavior, and provides IoCs including Index.js, SHA256 b5a3ace8dc6cc03a5d83b2d85904d6e1ee00d4167eb3d04d4fb4f793c9903b7e, and C2 IP 45.63.39.209.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
