216.73.216.233

NodeLoader Exposed: The Node.js Malware Evading Detection

· Published 13/12/2024 22:59 · Modified 16/12/2024 12:03

Export JSON

Essential information

Published
13/12/2024 22:59
Modified
16/12/2024 12:03
Tags
2024-12-13 cryptocurrency miners evasion techniques game streaming information stealers lumma stealer node.js nodeloader social engineering
Related entities
6 techniques (mitre), 4 malware, 1 others

Description

Zscaler ThreatLabz discovered a malware campaign using applications for Windows to distribute and . Named , this malware family employs compiled executables to deliver second-stage payloads like XMRig, Lumma, and Phemedrone Stealer. The attackers use , targeting gamers through YouTube and Discord, leading them to malicious websites resembling legitimate gaming platforms. uses the sudo-prompt module for privilege escalation and employs various . The malware downloads and executes PowerShell scripts, which in turn download and run additional payloads. The use of and large file sizes complicates detection for some security products, resulting in low antivirus detection rates.

External references