216.73.217.22

Yet Another NodeJS Backdoor (YaNB): A Modern Challenge

· Published 16/05/2025 08:51 · Modified 21/05/2025 20:57

Export JSON

Essential information

Published
16/05/2025 08:51
Modified
21/05/2025 20:57
Tags
2025-05-16 anti-vm backdoor captcha kongtuke node.js nodejs rat persistence rat socks5 proxy system reconnaissance xor encryption
Related entities
11 observables, 1 intrusion sets (apt), 2 malware

Description

A resurgence in malicious campaigns exploiting deceptive verifications has been observed, tricking users into executing NodeJS-based backdoors and deploying sophisticated Remote Access Trojans. The attack begins with a malicious NodeJS script connecting to attacker-controlled infrastructure, remaining passive until further commands are received. An advanced variant capable of tunneling malicious traffic through SOCKS5 proxies and using XOR-based encryption was uncovered. The campaign, known as , uses compromised websites as initial access points. The malware employs mechanisms, collects system information, and establishes . It includes features for command execution, payload dropping, and covert communication. The 's functionality includes detailed , remote command execution, and network traffic tunneling.

External references