Cybersecurity
Node.js used to deliver malware in targeted attacks
Symantec said attackers had used Node.js in attacks since February 2026 against government departments, technology companies and hotels, while GuidePoint Security described a separate ClickFix campaign affecting at least 31 organisations.
- Symantec Threat Hunter Team said attackers had used Node.js in cyber intrusions targeting government departments, technology companies and hotels since February 2026.
- In one intrusion against an unspecified Asian technology company, attackers downloaded the official Node.js installer and used it to deploy a malicious implant through EtherHiding.
- Symantec said similar activity had involved ModeloRAT and Mistic, which it assessed as being linked to KongTuke, also called Woodgnat.
- GuidePoint Security said a separate ClickFix campaign had compromised at least 31 organisations and had used fake CAPTCHA prompts to deliver a persistent backdoor.
Symantec Threat Hunter Team said multiple attackers had used Node.js in cyber intrusions since February 2026, targeting government departments, technology companies and hotels. It said node.exe was attractive because it was a legitimate signed tool and because script-based payloads were less likely to trigger signature checks.
In one intrusion against an unnamed Asian technology company, which Symantec said ran from 23 March to 25 July 2026, the attackers downloaded the official Node.js installer from nodejs.org. Symantec said they then used the runtime to install a malicious implant for long-term access and command retrieval through EtherHiding, after ClickFix had given them access.
Symantec said the same approach had also appeared with ModeloRAT and Mistic, which it assessed as the work of KongTuke, also called Woodgnat. The company said earlier Woodgnat chains had used node.exe to run attacker JavaScript and to chain PowerShell and Windows command-line tools, along with the NexShield browser extension and the GateKeeper .NET payload.
Symantec also linked the method to a U.S. fintech organisation. It said Zscaler ThreatLabz had documented C2Looper last month, while the earliest activity in that case dated to 6 May 2026 and had first involved AdaptixC2 and a Cobalt Strike Beacon.
GuidePoint Security said a separate ClickFix campaign had compromised at least 31 organisations, including e-commerce, professional services and retail logistics businesses. Jean-Pierre Mouton said the campaign used the Polygon blockchain as a way to update C2 details, and GuidePoint advised website checks, browser-extension controls and staff training.
Named in this story
People
- Jean-Pierre Mouton
- was the GuidePoint Security researcher quoted on the campaign
Companies
- Broadcom
- owns Symantec's cybersecurity division
- GuidePoint Security
- said a separate ClickFix campaign had compromised at least 31 organisations
Organisations
- Symantec Threat Hunter Team
- published the report on the attack chains
- KongTuke
- was the initial access broker Symantec linked to the activity
- Zscaler ThreatLabz
- had documented C2Looper the previous month
Products and systems
- Node.js
- was abused as the runtime for payload delivery
- ClickFix
- was used as the social engineering method for initial access
- EtherHiding
- was used to locate command-and-control details and retrieve commands
- AdaptixC2
- was one of the tools attackers tried to deploy
- Cobalt Strike
- was one of the tools attackers tried to deploy
- ModeloRAT
- appeared alongside the Node.js abuse in some attacks
- Mistic
- appeared alongside the Node.js abuse in some attacks
- C2Looper
- was the Rust-based backdoor deployed in one intrusion
- GateKeeper
- was a .NET payload used in the attacks
- NexShield
- was a malicious Chrome extension used in the attacks
How the source tells it
The piece read like a security alert, with a generally urgent register but little overt flourish.
- urgency recent incidents, active timelines and closing mitigation advice kept the story in alert mode