Node.js: Old Technique Makes a Comeback
Attackers are reviving the abuse of the Node.js runtime to execute malicious JavaScript payloads and evade signature-based detection. In multiple intrusions since February 2026, threat actors including initial access broker Woodgnat have used Node.js implants for persistence via registry Run keys and command-and-control via Ethereum blockchain smart contracts (EtherHiding). The technique has been observed alongside tools like ModeloRAT, C2Looper, and Backdoor.Mistic in attacks targeting government, technology, and financial sectors.
- domainapi[.]datalayerservice[.]comC2 subdomain.
- domainapi[.]technodatabase[.]netC2 domain.
- domainauthorized-logins[.]netMalicious domain.
- domainb6w9m2z5x8q1v3k[.]topMalicious domain.
- domainbestopebel[.]plMalicious domain.
- domainbookphotohot[.]proMalicious domain.
- domainbookphotoreserv[.]proMalicious domain.
- domaincarrolc[.]comMalicious domain.
- domainchallenge-refernow[.]comMalicious domain.
- domainchat[.]devminelimited[.]comC2 domain.
- domainchat[.]doctecsolutions[.]comC2 domain.
- domaincj06y9v4xab[.]comMalicious domain.
- domaincsa-humanchecknow[.]comMalicious domain.
- domaincwrtwright[.]comMalicious domain.
- domaindatalayerservice[.]comC2 domain used by Cobalt Strike Beacon and AdaptixC2, spoofing database-related traffic to blend in.
- domaindefs[.]updater-worelos[.]comMalicious domain.
- domaindesign[.]devminelimited[.]comC2 subdomain.
- domaindevminelimited[.]comSpoofed domain of Devmine used for C2 infrastructure.
- domaindocs[.]datalayerservice[.]comC2 subdomain.
- domaindrivefeedback[.]comMalicious domain.
- domaineth[.]llamarpc[.]comEthereum blockchain RPC gateway used by node.exe implant for EtherHiding.
- domainformulario[.]puentelargo[.]orgMalicious domain.
- domainftps[.]upd-domain-goloro[.]comMalicious domain.
- domaingrande-luna[.]topMalicious domain.
- domainhelthfulcore[.]infoMalicious domain.
- domainhuman-check[.]topMalicious domain.
- domainjoincroud[.]infoMalicious domain.
- domainjokesprite[.]infoMalicious domain.
- domainjusthandsoff[.]infoMalicious domain.
- domainkedvs4wiykc[.]comMalicious domain.
- domainkiptownim[.]infoMalicious domain.
- domainklassniylink124[.]comMalicious domain.
- domainlegaar[.]comMalicious domain.
- domainmail[.]authorized-logins[.]netMalicious domain.
- domainmailes[.]upd-domain-goloro[.]comMalicious domain.
- domainmails[.]updater-worelos[.]comMalicious domain.
- domainmainnet[.]gateway[.]tenderly[.]coEthereum blockchain RPC gateway used by node.exe implant for EtherHiding.
- domainmicrosoft[.]desereyunton[.]workers[.]devCloudflare domain abused for C2 communication by node.exe implant.
- domainministrew[.]infoMalicious domain.
- domainmueleer[.]comMalicious domain.
- domainnano[.]upscale-kolo[.]comMalicious domain.
- domainninetyorigins[.]comMalicious domain.
- domainnotstorageapis[.]comMalicious domain.
- domainoeannon[.]comMalicious domain.
- domainpartner-conflrmpanel[.]comMalicious domain.
- domainperiod-checkavaldx[.]comMalicious domain.
- domainphotbookguest[.]proMalicious domain.
- domainphp[.]authorized-logins[.]netMalicious domain.
- domainplanner[.]devminelimited[.]comC2 subdomain.
- domainrebronzeal[.]comC2 domain contacted by PowerShell script for beaconing over a multi-month period.
- domainrecepyman[.]infoMalicious domain.
- domainresources[.]datalayerservice[.]comC2 subdomain.
- domainrotoa-upda-lo[.]comMalicious domain.
- domainrs2y15sungu[.]comMalicious domain.
- domainsafedocphoto[.]infoMalicious domain.
- domainsimsracing[.]netMalicious domain.
- domainsql-updater-service[.]comMalicious domain.
- domainsrv[.]doctecsolutions[.]comC2 subdomain.
- domainsss[.]authorized-logins[.]netMalicious domain.
- domainstrapness[.]comDomain used to fetch and run an initial PowerShell script via ClickFix technique.
- domainsummonhood[.]comInitial C2 domain contacted by PowerShell script early in the intrusion.
- domainthomphon[.]comMalicious domain.
- domaintoogwido[.]sa[.]comMalicious domain.
- domainupdater-worelos[.]comMalicious domain.
- domainupdate[.]update-fall[.]comMalicious domain.
- domainupd-domain-goloro[.]comMalicious domain.
- domainupscale-kolo[.]comMalicious domain.
- domainvideo[.]technodatabase[.]netC2 domain.
- domainvisa-safedocs[.]infoMalicious domain.
- domainw3xasv14culvnqj[.]topMalicious domain.
- filenameCSIDL_COMMON_APPDATA\weightlessing\earthquakeist.ps1Oddly named folder under common application-data directory containing PowerShell script.
- filenameCSIDL_PROFILE\appdata\local\microsoft\windowsapps\cache\m4hxy87f\5w3wd\node.exePath to signed Node.js runtime used as implant vehicle.
- filenameCSIDL_PROFILE\appdata\local\microsoft\windowsapps\cache\m4hxy87f\skjywq4ppx.datData file passed as argument to node.exe, likely holding JavaScript or bytecode payload.
- filenameCSIDL_PROFILE\appdata\local\temp\main.x64a.exePath to blocked AdaptixC2 agent binary.
- filenameCSIDL_PROFILE\appdata\local\temp\thread.exePath to blocked Cobalt Strike Beacon binary.
- filenameCSIDL_PROFILE\appdata\local\temp\thread_indirect.exePath to Cobalt Strike Beacon binary.
- ip142[.]93[.]242[.]144Malicious network indicator.
- ip144[.]31[.]53[.]78Malicious network indicator.
- ip178[.]16[.]55[.]232Backing infrastructure for rebronzeal.com C2.
- ip185[.]205[.]211[.]217Backing infrastructure for rebronzeal.com C2.
- ip198[.]13[.]159[.]44Malicious network indicator.
- ip199[.]231[.]70[.]175Likely staging server for AdaptixC2 agent.
- ip199[.]91[.]221[.]42Malicious network indicator.
- ip45[.]158[.]196[.]23C2 IP address for C2Looper backdoor on port 8888.
- registry_keyHKCU\Software\Microsoft\Windows\CurrentVersion\RunRun key used for persistence of node.exe implant via conhost.exe.
- sha25608ea6bcce44b13813b321599b1ec88bb2c61314106286eca60402f7e738f3c4dagentdiags.exe - AdaptixC2 agent
- sha256164cad33a0b076a6d01263e159ad06d2e7b1e9e1ace43294c252b11699022485SHA256 hash of evasion.node, a native Node.js addon used by the implant.
- sha256
- sha256
- sha2561e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984Backdoor.Mistic Loader
- sha256
- sha256
- sha256
- sha25624d71cb6cf6d34871031564c3f104195b812f8e72ceffb1f0ce1936998531e6faccumulatally.ps1 - PowerShell script
- sha256
- sha25634d798a6c55e57ed0932b6499f4fbcb5454bdfca903307be101a0594b0ac07bcFake lock screen
- sha256
- sha256
- sha256466762502123d91be56d9c5a3b92a55c7e3a8c8939a3006cfaee565440ffe5e4cobol64.exe - AdaptixC2 agent
- sha25659358233a269ce587a1b24ca35e79ab294ce560b43555b500d02cf03687c4fcfthread_indirect.exe - Cobalt Strike Beacon
- sha256
- sha2565a27de542f8e4f5f9020baea00ff9e92a5d9a76e3c5143bcfccb55a4ab0be351thread.exe - Cobalt Strike Beacon
- sha256
- sha256
- sha256
- sha2568238fa99927aea6a6837792e5c8122ecd9458dd1164a8fd6c86da6794278bcefage.exe - AdaptixC2 agent
- sha256
- sha256
- sha256
- sha256
- sha256
- sha256
- sha256
- sha256
- sha256c854382d457eddbae9887350f9f19a2bc35c02968900b8f534503d0dcbd824a5SHA256 hash of xhelper64.exe, a Rust-based backdoor (C2Looper).
- sha256cd211247d1c1c1ca4d77418fea60efafd0736017ef35c9191aed85c684adc153agent_startup.exe - Suspicious file
- sha256
- sha256
- sha256
- sha256
- sha256
- sha256d965de63dbd27abb00efeb9bea029cd38952dc5c268b61a522b2358d8452e43amain.x64a.exe - AdaptixC2 agent
- sha256
- sha256e237801a9ef693d0d4c7d148965bb50c90946b43b8b9e00aa5e39fe5393a26e9earthquakeist.ps1 - PowerShell script
- sha256e901df53873d5379ad9399c63d3e014c7be188a7599b32e5b36b1de1cf7d5fbaage64.exe - AdaptixC2 agent
- sha256
- sha256
- sha256
- urlhxxp://178[.]16[.]54[.]253/~extranet/phot7482[.]exeMalicious download URL.
- urlhxxp://178[.]16[.]54[.]253/~extranet/Tmsyz[.]exeMalicious download URL.
- urlhxxp://193[.]58[.]122[.]42/files/hvnc2[.]exeMalicious download URL.
- urlhxxp://193[.]58[.]122[.]42/files/rat1[.]exeMalicious download URL.
- urlhxxp://193[.]58[.]122[.]42/files/rat[.]exeMalicious download URL.
- urlhxxp://193[.]58[.]122[.]42/files/stil1[.]exeMalicious download URL.
- urlhxxp://193[.]58[.]122[.]42/files/stil[.]exeMalicious download URL.
- urlhxxp://199[.]231[.]70[.]175:443/update[.]aspxLikely staging server URL for AdaptixC2 agent download.
- urlhxxp://94[.]156[.]114[.]250/files/lasttry[.]exeMalicious download URL.
- urlhxxps://toogwido[.]sa[.]com/Ca[.]ps1Malicious PowerShell script download URL.
- urlhxxps://www[.]xt24[.]com/install/update[.]ps1Malicious PowerShell script download URL.
- urlhxxp://thomphon[.]com/update[.]msiMalicious download URL.
Detection / Hunteropenrouter
What Happened
Attackers are using a legitimate programming tool called Node.js to hide their malicious activities from security software. Because Node.js is a trusted developer tool, security programs are less likely to flag it as dangerous. The attackers use it to run hidden code that can steal data or maintain access to a compromised computer. In some cases, they have hidden their command instructions inside the Ethereum blockchain, a public digital ledger, making it very difficult to block the attacks. Organizations in technology, government, and finance have been targeted. Defenders should monitor for the unexpected use of Node.js and unusual network connections to blockchain services.
Key Takeaways
- Attackers are abusing the legitimate, signed Node.js runtime (node.exe) to execute malicious JavaScript payloads, evading signature-based detection.
- Node.js implants are using Ethereum blockchain RPC gateways (EtherHiding) to retrieve commands or payloads hidden in smart contracts.
- The ClickFix technique is used for initial access, prompting victims to paste and run obfuscated PowerShell commands via the Windows Run dialog.
- Multiple threat actors, including initial access broker Woodgnat (aka KongTuke), are utilizing Node.js alongside tools like ModeloRAT, Backdoor.Mistic, and C2Looper.
- Persistence is achieved via registry Run keys that relaunch node.exe headlessly through conhost.exe at every login.
Affected Systems
- Windows systems
- Organizations using Active Directory
- Government departments
- Technology companies
- Hotels in Asia
- U.S. financial organizations
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: ClickFix technique used to trick users into pasting obfuscated PowerShell commands into Windows Run dialog.
- Execution: PowerShell scripts (e.g., accumulatally.ps1, earthquakeist.ps1) downloaded and executed as services for persistence.
- Persistence: Registry Run key entry added to relaunch node.exe headlessly via conhost.exe at every login.
- Defense Evasion: Node.js runtime (node.exe) downloaded from official site and used to execute malicious JavaScript payloads (evasion.node) to evade signature-based detection.
- Command and Control: Node.js implant communicates with Ethereum blockchain RPC gateways (EtherHiding) and Cloudflare Workers domains to retrieve commands or payloads.
- Discovery: Active Directory reconnaissance conducted using net.exe to enumerate domain computers.
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
No detection rules are provided in the article. The article references the Symantec Protection Bulletin for protection updates.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | EDR can detect process execution, registry modifications, and PowerShell activity. However, the use of legitimate signed binaries like node.exe and conhost.exe may blend in with normal developer activity. |
| Network Visibility | Medium | Network connections to C2 domains and Ethereum RPC gateways are visible, but traffic to legitimate blockchain services may not be inherently suspicious without behavioral context. |
| Detection Difficulty | Moderate | Detection requires distinguishing legitimate Node.js usage from malicious use. Behavioral indicators like unusual file paths, registry Run key modifications, and connections to blockchain RPC gateways can aid detection. |
Required Log Sources
- Process creation logs
- Registry modification logs
- PowerShell script block logs
- DNS logs
- HTTP/HTTPS proxy logs
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for node.exe executing from unusual paths such as Windows Apps cache directories. | Process execution logs with full command line and file path information. | Execution | Medium - Developers may run Node.js from various locations, but cache directories are atypical. |
| Consider hunting for conhost.exe used to launch node.exe headlessly as a persistence mechanism. | Process ancestry and command line logs. | Persistence | Low - Headless execution of Node.js via conhost.exe is unusual. |
| Consider hunting for registry Run key entries that reference node.exe or conhost.exe. | Registry modification logs (e.g., Sysmon Event ID 13). | Persistence | Low - Legitimate software rarely uses this specific combination for persistence. |
| Consider hunting for PowerShell scripts launched as Windows services with beaconing network behavior. | Service creation logs, process execution logs, and network connection logs. | Persistence | Medium - Some legitimate administrative scripts may exhibit similar behavior. |
| Consider hunting for node.exe making outbound connections to Ethereum blockchain RPC gateways. | Network connection logs and DNS resolution logs. | Command and Control | Medium - Legitimate blockchain applications may also connect to these services. |
Control Gaps
- Signature-based AV may miss malicious logic stored in interpreted JavaScript files executed by legitimate node.exe.
- Network firewalls may not block traffic to legitimate Ethereum RPC gateways used for C2.
- Application whitelisting may allow node.exe due to its trusted, signed status.
Key Behavioral Indicators
- node.exe executing from Windows Apps cache directories
- conhost.exe used to launch node.exe with a .dat file argument
- Registry Run key entries referencing conhost.exe and node.exe
- PowerShell scripts running as services with near-daily beaconing cadence
- node.exe making repeated HTTPS connections to Ethereum RPC gateways
False Positive Assessment
Medium - Node.js is a legitimate developer tool, and blockchain RPC gateways have legitimate uses. Distinguishing malicious use requires behavioral context such as unusual file paths, persistence mechanisms, and network beaconing patterns.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider searching endpoint telemetry for the listed IOCs, particularly node.exe executing from cache directories or with .dat file arguments.
- If your EDR supports host isolation, consider isolating any hosts showing beaconing behavior to rebronzeal.com or datalayerservice.com.
- Consider blocking the listed C2 domains and IPs at your firewall or proxy if they are not used for legitimate business purposes.
Infrastructure Hardening
- Evaluate whether your organization needs outbound access to Ethereum blockchain RPC gateways. If not, consider blocking them at the network level.
- Consider implementing network segmentation to restrict PowerShell from making direct outbound connections to non-corporate domains.
- If applicable, evaluate application control policies to restrict node.exe execution to approved directories and users.
User Protection
- Consider deploying endpoint detection rules for registry Run key modifications involving conhost.exe or node.exe.
- If your EDR supports it, consider monitoring for ClickFix-style attacks by alerting on obfuscated PowerShell commands executed from the Run dialog.
- Evaluate whether your email security gateway can detect and block ClickFix lure pages.
Security Awareness
- Consider adding ClickFix techniques to existing security awareness training, emphasizing the risks of pasting and running unknown commands.
- Remind employees to verify the source of any software installers, even those from official sites, if they were not requested by IT.
- Consider training developers on the risks of abusing legitimate tools like Node.js and how attackers may leverage them for evasion.
MITRE ATT&CK Mapping
Execution
Persistence
Stealth
Discovery
Command and Control
Additional IOCs
- Ips:
142[.]93[.]242[.]144- Malicious network indicator.144[.]31[.]53[.]78- Malicious network indicator.198[.]13[.]159[.]44- Malicious network indicator.199[.]91[.]221[.]42- Malicious network indicator.185[.]205[.]211[.]217- Backing infrastructure for rebronzeal.com C2.178[.]16[.]55[.]232- Backing infrastructure for rebronzeal.com C2.199[.]231[.]70[.]175- Likely staging server for AdaptixC2 agent.
- Domains:
eth[.]llamarpc[.]com- Ethereum blockchain RPC gateway used by node.exe implant for EtherHiding.mainnet[.]gateway[.]tenderly[.]co- Ethereum blockchain RPC gateway used by node.exe implant for EtherHiding.chat[.]doctecsolutions[.]com- C2 domain.design[.]devminelimited[.]com- C2 subdomain.planner[.]devminelimited[.]com- C2 subdomain.video[.]technodatabase[.]net- C2 domain.api[.]technodatabase[.]net- C2 domain.chat[.]devminelimited[.]com- C2 domain.docs[.]datalayerservice[.]com- C2 subdomain.api[.]datalayerservice[.]com- C2 subdomain.resources[.]datalayerservice[.]com- C2 subdomain.srv[.]doctecsolutions[.]com- C2 subdomain.authorized-logins[.]net- Malicious domain.b6w9m2z5x8q1v3k[.]top- Malicious domain.bestopebel[.]pl- Malicious domain.bookphotohot[.]pro- Malicious domain.bookphotoreserv[.]pro- Malicious domain.carrolc[.]com- Malicious domain.challenge-refernow[.]com- Malicious domain.cj06y9v4xab[.]com- Malicious domain.csa-humanchecknow[.]com- Malicious domain.cwrtwright[.]com- Malicious domain.defs[.]updater-worelos[.]com- Malicious domain.drivefeedback[.]com- Malicious domain.formulario[.]puentelargo[.]org- Malicious domain.ftps[.]upd-domain-goloro[.]com- Malicious domain.grande-luna[.]top- Malicious domain.helthfulcore[.]info- Malicious domain.human-check[.]top- Malicious domain.joincroud[.]info- Malicious domain.jokesprite[.]info- Malicious domain.justhandsoff[.]info- Malicious domain.kedvs4wiykc[.]com- Malicious domain.kiptownim[.]info- Malicious domain.klassniylink124[.]com- Malicious domain.legaar[.]com- Malicious domain.mail[.]authorized-logins[.]net- Malicious domain.mailes[.]upd-domain-goloro[.]com- Malicious domain.mails[.]updater-worelos[.]com- Malicious domain.ministrew[.]info- Malicious domain.mueleer[.]com- Malicious domain.nano[.]upscale-kolo[.]com- Malicious domain.ninetyorigins[.]com- Malicious domain.notstorageapis[.]com- Malicious domain.oeannon[.]com- Malicious domain.partner-conflrmpanel[.]com- Malicious domain.period-checkavaldx[.]com- Malicious domain.photbookguest[.]pro- Malicious domain.php[.]authorized-logins[.]net- Malicious domain.recepyman[.]info- Malicious domain.rotoa-upda-lo[.]com- Malicious domain.rs2y15sungu[.]com- Malicious domain.safedocphoto[.]info- Malicious domain.simsracing[.]net- Malicious domain.sql-updater-service[.]com- Malicious domain.sss[.]authorized-logins[.]net- Malicious domain.thomphon[.]com- Malicious domain.toogwido[.]sa[.]com- Malicious domain.upd-domain-goloro[.]com- Malicious domain.update[.]update-fall[.]com- Malicious domain.updater-worelos[.]com- Malicious domain.upscale-kolo[.]com- Malicious domain.visa-safedocs[.]info- Malicious domain.w3xasv14culvnqj[.]top- Malicious domain.
- Urls:
hxxp://178[.]16[.]54[.]253/~extranet/Tmsyz.exe- Malicious download URL.hxxp://178[.]16[.]54[.]253/~extranet/phot7482.exe- Malicious download URL.hxxp://193[.]58[.]122[.]42/files/hvnc2.exe- Malicious download URL.hxxp://193[.]58[.]122[.]42/files/rat.exe- Malicious download URL.hxxp://193[.]58[.]122[.]42/files/rat1.exe- Malicious download URL.hxxp://193[.]58[.]122[.]42/files/stil.exe- Malicious download URL.hxxp://193[.]58[.]122[.]42/files/stil1.exe- Malicious download URL.hxxp://94[.]156[.]114[.]250/files/lasttry.exe- Malicious download URL.hxxp://thomphon[.]com/update.msi- Malicious download URL.hxxps://toogwido[.]sa[.]com/Ca.ps1- Malicious PowerShell script download URL.hxxps://www[.]xt24[.]com/install/update.ps1- Malicious PowerShell script download URL.
- File Hashes:
e901df53873d5379ad9399c63d3e014c7be188a7599b32e5b36b1de1cf7d5fba(SHA256) - age64.exe - AdaptixC2 agentd965de63dbd27abb00efeb9bea029cd38952dc5c268b61a522b2358d8452e43a(SHA256) - main.x64a.exe - AdaptixC2 agent24d71cb6cf6d34871031564c3f104195b812f8e72ceffb1f0ce1936998531e6f(SHA256) - accumulatally.ps1 - PowerShell script8238fa99927aea6a6837792e5c8122ecd9458dd1164a8fd6c86da6794278bcef(SHA256) - age.exe - AdaptixC2 agent5a27de542f8e4f5f9020baea00ff9e92a5d9a76e3c5143bcfccb55a4ab0be351(SHA256) - thread.exe - Cobalt Strike Beacon59358233a269ce587a1b24ca35e79ab294ce560b43555b500d02cf03687c4fcf(SHA256) - thread_indirect.exe - Cobalt Strike Beacone237801a9ef693d0d4c7d148965bb50c90946b43b8b9e00aa5e39fe5393a26e9(SHA256) - earthquakeist.ps1 - PowerShell script08ea6bcce44b13813b321599b1ec88bb2c61314106286eca60402f7e738f3c4d(SHA256) - agentdiags.exe - AdaptixC2 agentcd211247d1c1c1ca4d77418fea60efafd0736017ef35c9191aed85c684adc153(SHA256) - agent_startup.exe - Suspicious file466762502123d91be56d9c5a3b92a55c7e3a8c8939a3006cfaee565440ffe5e4(SHA256) - cobol64.exe - AdaptixC2 agent1a8739e2dedebc971743dd0c985526f2373f871f9c31c5b2258a5e8b373e4df2(SHA256) - AsukaStealer1d09357b6a096fdc35cd5c873eed15665d6b3c879d20c8cf01e6bca0005512cf(SHA256) - Backdoor.Mistic1e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984(SHA256) - Backdoor.Mistic Loader1fc515870c681bf3e1b7947e2248bbcfe9918db2978117e91134de20bd42fd6a(SHA256) - Backdoor.Mistic210615866cd2923cc0840f196eb12c00feee113e43850376803c8e024f7e63ce(SHA256) - Suspicious file232b5115f4b78fe01c6497b1039b85ee57f6a58abd095dc80ea4d3c5e6cef6d6(SHA256) - Suspicious file2cd88d5280a61714836f5f07a16df190911c5b952af2998dbbcda910b3b1c494(SHA256) - Backdoor.Mistic34d798a6c55e57ed0932b6499f4fbcb5454bdfca903307be101a0594b0ac07bc(SHA256) - Fake lock screen374d7008d9ba33b440d1838561f59d936a25092e4dc60def6346a9486a799906(SHA256) - Bootstrap3f797a639bc855bc6d5471f327924b62d10900ddec49b970eca6604142bbb4be(SHA256) - Backdoor.Mistic59e3c4cb06331b4f2d78a9a0592f3747e573bd01c5a7650c26361d1e25520712(SHA256) - Backdoor.Mistic72db2ea09c8d4e09ef99e1342b42491a6aebf6008a1e5337131c8bde06b2ea22(SHA256) - Suspicious file7d4fb94f6b4623690daea67ed52e97705cb102f443988ff605f2a9c4898244dc(SHA256) - Backdoor.Mistic7f0754c3c3146efb451ac8e80ef6c3d61395e7974485b94e20ce436341a41240(SHA256) - Bootstrap83e970feb3f10692c164f6889f7a026f135c2433e5bf8e662a6e63a3b81267b7(SHA256) - Suspicious file8c935feec4bd05d5d918df308be417532fb42608fb989a08eab183e0ae699235(SHA256) - Suspicious file9e52cc90cff150abe21f0a6440e86e0a99ff383b81061b96def8948e21d0ac66(SHA256) - Backdoor.Mistica98dde0e43267e973bd88cb630791cb0b667b8a2e788dc47adf2e85e813eea86(SHA256) - Suspicious fileafd5f1ed45a9867daf3bc64152cef460a06b164c8183e490db39146d4749a82c(SHA256) - Backdoor.Misticb0f918666bb11e8f25956cdfe240bc26b4bd3192f93c123a056fe3df6801a5f5(SHA256) - Suspicious fileb2fe498de7a56646df1a00db3513a6c31eb660fa0405c00cdd2219f26c29ca23(SHA256) - Suspicious filebdd376d48d5ed482ed48e93ae80579b7c089a3c854225b97cf5f2291ebdb476b(SHA256) - EtherRATced6b0f44410f6133ad63b61e04613a8b56cc3338d7b34497540e9541163e7ec(SHA256) - Backdoor.Misticd2705499d24772fa25049f6a58d873a2ff6607d01c64622e85977e7d17d5df41(SHA256) - Backdoor.Misticd2c60d76e65f547baa13f156470b10f8059082be5603a6e04dd75315043c0a50(SHA256) - Suspicious filed2c637235d62ad766f961f9b8563f6a0e6db2ec0a343470385991b4df826afbc(SHA256) - Backdoor.Misticd3e64a86909201f930c35b0f1e93e7a2c40a680e951d1fbb78b3047b8cb5c780(SHA256) - Suspicious filedb972979d508e75fe730d3b72c2701470fbdaeaf8ebdd674744754fa44438ca5(SHA256) - Backdoor.Misticebadfe4f370b6129402df7107581c7142c916aa7b0fae588540ab16beb5c4cae(SHA256) - Backdoor.Misticf591275a8f014b29e567529d67c54eb7bb4473db1c38737d6bfd5b3d52c9344e(SHA256) - Backdoor.Misticfb3630822b70bacb56aa4cec29b5a0e3e9acb3920809e70310a4003385a6d34a(SHA256) - Backdoor.Mistic
- Registry Keys:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run- Run key used for persistence of node.exe implant via conhost.exe.
- File Paths:
CSIDL_COMMON_APPDATA\weightlessing\earthquakeist.ps1- Oddly named folder under common application-data directory containing PowerShell script.CSIDL_PROFILE\appdata\local\temp\thread_indirect.exe- Path to Cobalt Strike Beacon binary.CSIDL_PROFILE\appdata\local\microsoft\windowsapps\cache\m4hxy87f\5w3wd\node.exe- Path to signed Node.js runtime used as implant vehicle.CSIDL_PROFILE\appdata\local\microsoft\windowsapps\cache\m4hxy87f\skjywq4ppx.dat- Data file passed as argument to node.exe, likely holding JavaScript or bytecode payload.CSIDL_PROFILE\appdata\local\temp\main.x64a.exe- Path to blocked AdaptixC2 agent binary.CSIDL_PROFILE\appdata\local\temp\thread.exe- Path to blocked Cobalt Strike Beacon binary.
- Command Lines:
- Purpose: Initial access via ClickFix lure executing obfuscated PowerShell to download script | Tools:
powershell.exe| Stage: Initial Access |powershell.exe -wInDOwS MINiMiz - Purpose: Active Directory reconnaissance enumerating domain computers | Tools:
net.exe| Stage: Discovery |net.exe group "domain computers" /dom - Purpose: Persistence via registry Run key to relaunch node.exe headlessly | Tools:
reg.exe,conhost.exe,node.exe| Stage: Persistence - Purpose: Network fingerprinting to check public IP address | Tools:
curl| Stage: Discovery |curl ip.me
- Purpose: Initial access via ClickFix lure executing obfuscated PowerShell to download script | Tools: