Hacking

Node.js Abuse and EtherHiding Power New Cyber Attacks

Published  ·  5 min read

Node.js

There exists a clever method employed by threat actors to maintain their stealth. They're using Node.js a legitimate, signed developer tool to run malicious code. Since February 2026, this trick has been used to hit government departments, tech companies, and hotels.

Symantec's Threat Hunter Team spotted the trend. The appeal is pretty simple: node.exe is a trusted binary. The bad stuff lives in scripts, not executables. That makes it harder for security tools to flag. And with a quick Registry tweak, the malware relaunches every time someone logs in.

Here's what's going on.

Quick Summary

What

Details

Method

Node.js runtime abuse

Targets

Government, tech firms, hotels

Timeline

Since February 2026

Key Technique

EtherHiding for C2

Notable Malware

C2Looper, ModeloRAT, Mistic

Attribution

KongTuke (Woodgnat)

The Node.js Trick

Attackers download the official Node.js installer from nodejs[.]org. They use the signed, trusted runtime to run their malicious scripts. The payload stays hidden because it's not a binary, it's just a script.

Here's how it's done:

  • Node.js is a legitimate tool, which means no alarms are going off
  • The malware resides in scripts rather than executable files
  • Detection based on signature cannot find it easily
  • It utilizes a Registry Run key for persistence

A Real-World Example:

In one attack against an Asian tech company, the attackers tried to deploy AdaptixC2 and Cobalt Strike. Both were blocked. So they switched to Node.js. That worked. They got their foothold.

The ClickFix Connection

ClickFix is a social engineering trick. Attackers show you a fake error or CAPTCHA and tell you to copy and paste a command to "fix" it. You paste it into Terminal or Run, and boom you've just compromised your own system.

The Two-Pronged Attack:

GuidePoint Security found that at least 31 organizations have been hit by ClickFix campaigns.

Who Gets Hurt:

  • The business whose website gets injected with the fake prompt
  • The visitor who falls for it and runs the command

The Blockchain Evasion:

"Traditionally, ClickFix malware can be neutralized by blocking the attacker's C2 server," said Jean-Pierre Mouton of GuidePoint Security. "This campaign sidesteps that defense by using the Polygon cryptocurrency blockchain as a dynamically updatable address book."

"Because it allows for ad hoc adjustment of C2 details at scale, blocking a singular domain or IP address alone does not permanently sever attacker access. For fractions of a cent per transaction, the attacker can redirect every infected machine to a new C2 server automatically."

EtherHiding: The Blockchain C2

EtherHiding uses blockchain as a dead drop for C2 addresses. The malware pulls its command-and-control location from the blockchain.

Why It's So Effective:

  • No single domain or IP to block
  • C2 can be changed instantly
  • Costs almost nothing
  • It's nearly impossible to shut down

The Malware They're Using

C2Looper:

A Rust-based backdoor first spotted by Zscaler. It was deployed against a U.S. fintech company. The installation happened more than two months after initial access.

ModeloRAT and Mistic (MLTBackdoor):

Both linked to KongTuke (aka Woodgnat), an initial access broker. These are often used alongside Node.js.

AsukaStealer:

A Node.js version of an information stealer. Used in multiple attacks.

GateKeeper:

A .NET payload with layered encryption and victim-fingerprinting.

The KongTuke Connection

KongTuke (aka Woodgnat) is an initial access broker. Their attack chains usually include:

  • Node.js to run malicious JavaScript
  • PowerShell and Windows command-line tools
  • A malicious Chrome extension called NexShield (a ClickFix variant called CrashFix)
  • GateKeeper .NET payload

What Symantec Found

Symantec saw multiple attackers using Node.js. They're mixing living-off-the-land tools, commodity malware, and new custom tools.

The Tools:

  • Node.js version of AsukaStealer
  • EtherRAT
  • Legitimate Microsoft utilities

The Takeaway:

"Attackers using Node.js appear happy to use a combination of both living-off-the-land and dual-use tools in their attacks, as well as commodity malware, and new tools such as Backdoor.Mistic, C2Looper, and the new version of AsukaStealer," Symantec concluded.

"This indicates that attackers with a variety of skill levels may be using Node.js as it has returned to popularity."

What You Should Do

For Organizations:

  • Check your websites for suspicious scripts
  • Restrict unauthorized browser extensions
  • Train employees to spot ClickFix

For Users:

  • Don't paste commands from websites into Terminal
  • Be skeptical of "copy and paste" instructions
  • Verify the source before following instructions

For Defenders:

  • Watch for Node.js running from unexpected locations
  • Look for Registry Run keys pointing to Node.js
  • Monitor for blockchain-related C2 activity

The Bottom Line

Attackers are using Node.js to stay hidden. It's a legitimate tool, so it flies under the radar. EtherHiding makes C2 infrastructure almost impossible to kill. ClickFix campaigns are hitting governments, tech firms, and hotels.

What You Need to Know:

Key Point

Detail

Method

Node.js runtime abuse

Targets

Government, tech firms, hotels

Timeline

Since February 2026

Key Technique

EtherHiding for C2

Notable Malware

C2Looper, ModeloRAT, Mistic

Attribution

KongTuke (Woodgnat)

What You Need to Do:

  • Audit websites for malicious scripts
  • Restrict browser extensions
  • Train employees on ClickFix
  • Monitor for Node.js from unexpected places

FAQ Section

What is the Node.js abuse technique?

Attackers use the legitimate Node.js runtime to run malicious scripts. Since Node.js is a signed, trusted tool, it doesn't trigger security alerts easily.

What is EtherHiding?

EtherHiding uses blockchain (Ethereum or Polygon) to store C2 addresses. This is difficult to block as there is no specific domain or IP address that can be blocked.

Who is behind these attacks?

The attacks are linked to KongTuke (aka Woodgnat), an initial access broker. Multiple groups are using Node.js now.

What is ClickFix?

ClickFix tricks users into copying and pasting commands from websites. The user thinks they're fixing a problem or proving they're human.

What should organizations do?

Audit websites, restrict browser extensions, train employees, and monitor for unusual Node.js activity.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067