www.security.com
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique
Article Content
Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts that evade signature-based detection. Notable incidents include the use of EtherHiding, where attackers download Node.js to execute implants that communicate with Ethereum blockchain gateways for commands. The attacks have involved various tools, including ModeloRAT and C2Looper, and have been attributed to the initial access broker known as KongTuke. The campaign has reportedly compromised at least 31 organizations through social engineering tactics like fake CAPTCHA prompts. The ongoing threat landscape indicates a significant resurgence of Node.js abuse among cybercriminals, with multiple actors employing this method for persistence and execution.
Key Points: • Node.js is being exploited by multiple threat actors since February 2026. • Attacks utilize the EtherHiding technique to evade detection via blockchain. • At least 31 organizations have been compromised through social engineering tactics.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.