logo

NodeLoader Used to Deliver Malware

ID: b75795a8-00a6-5946-af1b-17c1e988d9e5

STIX ID: report--b75795a8-00a6-5946-af1b-17c1e988d9e5

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Technical analysis of a malicious campaign leveraging a compiled Node.js loader (“NodeLoader”) that prompts UAC (via sudo-prompt), creates a hidden ProgramData folder, and downloads PowerShell scripts which deploy drop1.exe (stealers: Phemedrone/Lumma) and drop2.exe (an XMRig miner). The report describes defense-evasion (process checks, Defender exclusions, uninstalling updates, stopping EventLog), persistence via a created Windows service, shellcode-based injection for Lumma, low AV detection due to large pkg-compiled binaries, and provides IoCs and evidence of active cryptocurrency transactions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.