logo

Node.js: Old Technique Makes a Comeback

ID: 75b01bca-0610-5312-b17c-49db214d5e8f

STIX ID: report--75b01bca-0610-5312-b17c-49db214d5e8f

Feed Name: security.com

Threat Score
78/100

Date Published: 2026-09-03

Date Updated: 2026-09-11

Author: Threat Hunter Team

...
...

**Executive summary:** Symantec observed a resurgence of Node.js abuse since February–July 2026 where attackers install legitimate Node.js runtimes to execute malicious JavaScript, maintain persistence via Run keys and services, and retrieve commands or payloads from Ethereum smart contracts (EtherHiding); campaigns involved AdaptixC2, Cobalt Strike, ModeloRAT, EtherRAT, Backdoor.Mistic and a Rust backdoor (C2Looper), affected multiple sectors (government, fintech, tech, hotels), and include extensive file and network IOCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.