logo

Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays

ID: d75eb14b-53d6-5c38-9582-48321090976a

STIX ID: report--d75eb14b-53d6-5c38-9582-48321090976a

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-31

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

RoadK1ll is a lean, Node.js-based reverse-tunneling implant that creates an outbound WebSocket tunnel to attacker infrastructure, turning infected machines into stealthy relays for reaching internal systems. The report details a custom 5-byte-framed WebSocket protocol with multiple channel support, message types for DATA/CONNECT/CONNECTED/CLOSE/ERROR, persistence and reconnection behavior, and provides IoCs including Index.js, SHA256 b5a3ace8dc6cc03a5d83b2d85904d6e1ee00d4167eb3d04d4fb4f793c9903b7e, and C2 IP 45.63.39.209.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.