NodeLoader Exposed: The Node.js Malware Evading Detection
Essential information
- Published
- 13/12/2024 22:59
- Modified
- 16/12/2024 12:03
- Tags
- 2024-12-13 cryptocurrency miners evasion techniques game streaming information stealers lumma stealer node.js nodeloader social engineering
- Related entities
- 6 techniques (mitre), 4 malware, 1 others
Description
Zscaler ThreatLabz discovered a malware campaign using Node.js applications for Windows to distribute cryptocurrency miners and information stealers. Named NodeLoader, this malware family employs Node.js compiled executables to deliver second-stage payloads like XMRig, Lumma, and Phemedrone Stealer. The attackers use social engineering, targeting gamers through YouTube and Discord, leading them to malicious websites resembling legitimate gaming platforms. NodeLoader uses the sudo-prompt module for privilege escalation and employs various evasion techniques. The malware downloads and executes PowerShell scripts, which in turn download and run additional payloads. The use of Node.js and large file sizes complicates detection for some security products, resulting in low antivirus detection rates.