www.security.com
Node.js Exploitation in Ransomware Attacks Grows
Article Content
Since February 2026, multiple cyber actors have revived the abuse of Node.js to deploy ransomware and other malicious payloads, targeting government departments, technology firms, and hotels. Attackers exploit the trusted Node.js runtime, using it to execute malicious scripts while evading signature-based detection. Techniques such as EtherHiding, which utilizes blockchain technology to conceal commands, have been employed. Notable attacks include the compromise of an Asian technology company and a U.S. fintech firm, with tools like ModeloRAT and C2Looper being deployed. The Symantec Threat Hunter Team has linked these activities to an initial access broker known as Woodgnat (KongTuke). The resurgence of Node.js exploitation underscores the need for heightened security measures against these evolving threats.
Key Points: • Node.js is being exploited to deploy ransomware and evade detection. • Attackers use techniques like EtherHiding to conceal their activities. • Victims include government agencies, tech companies, and hotels.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.