RoadK1ll Malware Turns Compromised Hosts into Network Relay Points

RoadK1ll Malware Turns Compromised Hosts into Network Relay Points

First seen 31 Mar 2026, 08:01 UTC BleepingcomputerCybersecuritynewsScworld 76% similarity 67.5

Article Content

Browse articles
ThreatCluster

A new malware named RoadK1ll has been identified, allowing attackers to pivot within compromised networks. Discovered by Blackpoint during an incident response, RoadK1ll is a Node.js implant that communicates via a custom WebSocket protocol. Its primary function is to convert a single compromised machine into a relay point for attackers, enabling access to otherwise unreachable internal systems. The malware establishes an outbound WebSocket connection to attacker-controlled infrastructure, bypassing perimeter controls. It supports multiple concurrent connections and lacks traditional persistence mechanisms, operating only while its process is active. Blackpoint has shared indicators of compromise, including a hash for RoadK1ll and an IP address used for communication. The malware's stealthy operation makes it a significant concern for network security.

Key Points: • RoadK1ll malware enables attackers to pivot within networks undetected. • It uses a custom WebSocket protocol for covert communication. • The implant lacks traditional persistence, relying on active processes.

ThreatCluster AI

Timeline

2026-03-30
RoadK1ll malware identified by Blackpoint during incident response.
2026-03-31
Cybersecuritynews reports on RoadK1ll's capabilities.

Community

Browse all →

Tracked Entities in This Story