logo

RST TI Report Digest: 22 Dec 2025

ID: 0860cb56-983e-5172-abfd-cdfc2833e37f

STIX ID: report--0860cb56-983e-5172-abfd-cdfc2833e37f

Feed Name: RST Cloud Blog

Threat Score
75/100

Date Published: 2025-12-22

Date Updated: 2026-04-29

Author: RST Cloud

...
...

**GachiLoader** is a sophisticated Node.js malware used in a campaign leveraging compromised YouTube accounts; it employs strong obfuscation and anti-analysis measures and has two main variants — one that fetches secondary payloads from a C2 using system profiling and another that includes the Kidkadi payload which executes directly. Kidkadi uses an innovative PE-injection method altering legitimate DLLs to stealthily run malicious code; Check Point Research developed an open-source Node.js tracer to bypass anti-analysis and document the loader's actions, and the report includes numerous IoCs (IPs, domains, URLs, and many SHA-256 hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.