VMTech
Discuss a project

Symantec Tracks Node.js Runtime Abuse in Targeted Malware Campaigns

Symantec Tracks Node.js Runtime Abuse in Targeted Malware Campaigns

Threat actors have used the trusted Node.js JavaScript runtime to deploy malicious payloads in targeted attacks against government departments, technology companies and hotels since February 2026, Symantec Threat Hunter Team reports. The activity turns node.exe, the signed binary used to run Node.js, into a vehicle for attacker-controlled JavaScript rather than relying solely on conventional malware executables.

In an intrusion targeting an unspecified Asian technology company between March 23 and July 25, 2026, attackers downloaded the official Node.js installer from nodejs.org. They then used the runtime to deploy a malicious implant intended to maintain access and retrieve commands or tooling through EtherHiding.

A signed runtime used for persistence

Symantec said the technique is attractive because node.exe is a legitimate signed developer tool. Malicious logic can reside in interpreted scripts, which may be less likely to trigger signature-based detection than a binary payload. A Registry Run key can also relaunch the payload whenever a user logs in.

The attackers shifted to this approach after repeated attempts to deploy AdaptixC2 and Cobalt Strike beacons were blocked following initial access through ClickFix social engineering. ClickFix variants typically present an alleged error or verification task and persuade a user to copy a command into the Windows Run dialog or Windows Terminal.

The activity has also appeared alongside ModeloRAT and Mistic, also known as MLTBackdoor. Symantec assesses both as linked to the initial access broker KongTuke, also called Woodgnat. In June, Symantec described Woodgnat chains that used node.exe to execute malicious JavaScript, then chained PowerShell and Windows command-line tools. Those campaigns also used a malicious Chrome extension named NexShield in a ClickFix variant called CrashFix.

Backdoors and blockchain-based command discovery

Other tools observed in related attacks include GateKeeper, a .NET payload with layered encryption and victim-fingerprinting logic. A similar operating pattern affected a U.S. fintech organization and led to deployment of C2Looper, a Rust-based backdoor documented by Zscaler ThreatLabz.

The earliest observed activity in that incident was May 6, 2026, when attackers used a ClickFix-derived foothold to deploy an AdaptixC2 agent and Cobalt Strike Beacon. C2Looper was installed more than two months later. Symantec found no evidence of credential theft, lateral movement or destructive operations, and said it remains unclear whether the attackers achieved objectives beyond establishing the backdoor foothold.

GuidePoint Security separately reported a ClickFix campaign compromising at least 31 organizations across e-commerce, professional services and retail logistics. It used fake CAPTCHA prompts on compromised websites and EtherHiding to locate command-and-control infrastructure. GuidePoint said the attackers used the Polygon blockchain as a dynamically updatable address book, allowing command-and-control details to change without depending on a single fixed domain or IP address.

Defensive priorities

Symantec said multiple threat actors are now exploiting Node.js, using tools including a Node.js version of AsukaStealer, EtherRAT, Microsoft utilities and command-line tools, as well as newer malware such as Backdoor.Mistic and C2Looper. The pattern combines living-off-the-land techniques, dual-use software and commodity malware.

For businesses, the practical response is to continuously inspect public-facing websites for suspicious changes and injected scripts, restrict unapproved browser extensions, and train employees to identify ClickFix-style prompts before they paste commands into Windows.

#cybersecurity#nodejs#clickfix#malware
Open analytics
On the site 1 views
min read 4 03.09.2026
Instagram

Symantec Tracks Node.js Runtime Abuse in Targeted Malware Campaigns

Open the post on Instagram ↗