logo

CAPTCHA to Command: Trustwave Uncovers Stealthy NodeJS Backdoor Campaign

ID: 477c38e2-afa5-537d-9da4-d5584372b678

STIX ID: report--477c38e2-afa5-537d-9da4-d5584372b678

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2025-05-01

Date Updated: 2026-04-22

Author: Ddos

...
...

Trustwave SpiderLabs details the KongTuke campaign which compromises websites to trick visitors with fake CAPTCHA pages that lead to execution of PowerShell commands and deployment of modular NodeJS RATs and associated stealers; the malware uses anti-VM checks, XOR+gzip encrypted C2, persistence via the Windows Registry, and SOCKS5 proxy tunneling, and actors host second-stage payloads via TryCloudflare to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.