Yet Another NodeJS Backdoor (YaNB): A Modern Challenge
Essential information
- Published
- 16/05/2025 08:51
- Modified
- 21/05/2025 20:57
- Tags
- 2025-05-16 anti-vm backdoor captcha kongtuke node.js nodejs rat persistence rat socks5 proxy system reconnaissance xor encryption
- Related entities
- 11 observables, 1 intrusion sets (apt), 2 malware
Description
A resurgence in malicious campaigns exploiting deceptive CAPTCHA verifications has been observed, tricking users into executing NodeJS-based backdoors and deploying sophisticated Remote Access Trojans. The attack begins with a malicious NodeJS script connecting to attacker-controlled infrastructure, remaining passive until further commands are received. An advanced NodeJS RAT variant capable of tunneling malicious traffic through SOCKS5 proxies and using XOR-based encryption was uncovered. The campaign, known as KongTuke, uses compromised websites as initial access points. The malware employs anti-VM mechanisms, collects system information, and establishes persistence. It includes features for command execution, payload dropping, and covert communication. The RAT's functionality includes detailed system reconnaissance, remote command execution, and network traffic tunneling.