ThreatCluster

GachiLoader Uses Obfuscated Node.js Malware to Deploy Infostealer Payloads

First seen 18 Dec 2025, 21:53 UTC GbhackersCyberpress 37

Article Content

Browse articles
ThreatCluster

GachiLoader has been identified as a JS-based loader that deploys various payloads, including the Rhadamanthys infostealer, on compromised Windows systems. The malware is distributed through various channels, targeting users and organizations to extract sensitive information.