216.73.217.22

GachiLoader: Defeating Node.js Malware with API Tracing

· Published 17/12/2025 21:22 · Modified 21/12/2025 19:35

Export JSON

Essential information

Published
17/12/2025 21:22
Modified
21/12/2025 19:35
Tags
2025-12-17 anti-analysis api tracing gachiloader infostealer kidkadi malware node.js obfuscation pe injection rhadamanthys youtube
Related entities
10 observables, 10 techniques (mitre), 2 others

Description

A new distribution campaign utilizing compromised accounts to spread infostealers has been identified. The campaign employs , a heavily obfuscated loader, to deploy the . implements techniques and uses a novel method called Vectored Overloading. To aid analysis, researchers developed an open-source tracer tool. The campaign has affected over 100 videos with 220,000 views across 39 compromised accounts since December 2024. The evades detection, elevates privileges, and disables Windows Defender before retrieving its payload.

External references