logo

Stories from the SOC: Mystery of the postponed proxyware install

ID: 6740c8fb-8c30-55be-bf34-caaa27e52950

STIX ID: report--6740c8fb-8c30-55be-bf34-caaa27e52950

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2025-11-24

Date Updated: 2026-04-27

Author: Ben Nahorney; Sean Scully

...
...

A SOC investigation uncovered a multi-stage infection: a bundled disk-cleaner installer dropped a persistent Node.js-based JavaScript backdoor scheduled to run as SYSTEM and check in with a C2; days later the C2 returned a PowerShell command that used an in-memory download-cradle to execute a fetched PowerShell script which attempted to install proxyware as a scheduled service. The team detected the suspicious PowerShell activity, isolated the host, and prevented the final payload installation; the report includes IoCs, persistence details, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.