Node.js Exploitation in Ransomware Attacks Grows

Node.js Exploitation in Ransomware Attacks Grows

First seen 3 Sep 2026, 11:45 UTC SecurityThehackernewswww.security.comwww.stormshield.com 66.5

Article Content

Browse articles
ThreatCluster

Since February 2026, multiple cyber actors have revived the abuse of Node.js to deploy ransomware and other malicious payloads, targeting government departments, technology firms, and hotels. Attackers exploit the trusted Node.js runtime, using it to execute malicious scripts while evading signature-based detection. Techniques such as EtherHiding, which utilizes blockchain technology to conceal commands, have been employed. Notable attacks include the compromise of an Asian technology company and a U.S. fintech firm, with tools like ModeloRAT and C2Looper being deployed. The Symantec Threat Hunter Team has linked these activities to an initial access broker known as Woodgnat (KongTuke). The resurgence of Node.js exploitation underscores the need for heightened security measures against these evolving threats.

Key Points: • Node.js is being exploited to deploy ransomware and evade detection. • Attackers use techniques like EtherHiding to conceal their activities. • Victims include government agencies, tech companies, and hotels.

Timeline

2026-02-01
Node.js abuse observed
Symantec reports multiple actors using Node.js for cyber attacks since February 2026.
www.security.com
2026-03-23
Attack on Asian tech company
Attackers downloaded Node.js to deploy a malicious implant after their previous payloads were blocked.
The Hacker News
2026-06-01
C2Looper deployed
A Rust-based backdoor known as C2Looper was deployed in attacks against a U.S. fintech firm.
www.security.com
2026-09-03
Symantec report published
Symantec releases a report detailing the resurgence of Node.js exploitation in ransomware attacks.
www.security.com