Node.js Exploited in Ransomware Attacks Using EtherHiding Technique

Node.js Exploited in Ransomware Attacks Using EtherHiding Technique

First seen 3 Sep 2026, 11:45 UTC SecurityThehackernewswww.security.comwww.stormshield.comGround.News+3 70.2

Article Content

Browse articles
ThreatCluster

Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts that evade signature-based detection. Notable incidents include the use of EtherHiding, where attackers download Node.js to execute implants that communicate with Ethereum blockchain gateways for commands. The attacks have involved various tools, including ModeloRAT and C2Looper, and have been attributed to the initial access broker known as KongTuke. The campaign has reportedly compromised at least 31 organizations through social engineering tactics like fake CAPTCHA prompts. The ongoing threat landscape indicates a significant resurgence of Node.js abuse among cybercriminals, with multiple actors employing this method for persistence and execution.

Key Points: • Node.js is being exploited by multiple threat actors since February 2026. • Attacks utilize the EtherHiding technique to evade detection via blockchain. • At least 31 organizations have been compromised through social engineering tactics.

Ask AI about this cluster

Timeline

2026-02-01
Node.js abuse observed
Threat actors began exploiting Node.js for malicious payload deployment targeting various sectors.
Security
2026-03-23
Intrusion at Asian tech company
Attackers downloaded Node.js to deploy a malicious implant after previous payloads were blocked.
Thehackernews
2026-07-25
C2Looper deployed
A Rust-based backdoor was installed in a U.S. fintech organization following initial access.
Cybernoz
2026-09-03
Symantec report published
Symantec Threat Hunter Team released findings on the resurgence of Node.js exploitation in cyberattacks.
Security