logo

GachiLoader: Defeating Node.js Malware with API Tracing

ID: 41769873-e268-5a87-aaaf-9d140a743278

STIX ID: report--41769873-e268-5a87-aaaf-9d140a743278

Feed Name: Check Point Research

Threat Score
75/100

Date Published: 2025-12-17

Date Updated: 2026-04-27

Author: [email protected]

...
...

This report analyzes a sustained YouTube Ghost Network campaign that lures users with game cheats and cracked software to download malware; it details GachiLoader (an obfuscated Node.js loader), the Kidkadi native loader, and a novel PE-injection method called "Vectored Overloading" used to load the Rhadamanthys infostealer, and provides technical analysis, anti-analysis bypass methods, IoCs and PoC tooling for defenders and researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.