Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding Ransomware Access Brokers — Threadlinqs Intelligence
As of 2026-09-03, Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding Ransomware Access Brokers is a high-severity malware threat attributed to Woodgnat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-2304 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Woodgnat · FINANCIAL
Since February 2026, threat actors of varying skill levels have revived abuse of the legitimate, signed Node.js interpreter (node.exe) to execute malicious JavaScript payloads and evade
Symantec/Broadcom's Threat Hunter Team documents a resurgence of the node.exe living-off-the-land (LOTL) technique: because node.exe is a legitimate, code-signed developer runtime, adversaries proxy execution of malicious JavaScript through it, bypassing binary-reputation and signature-based controls that would flag an unsigned or unfamiliar executable. Victims are typically lured via ClickFix-style fake-CAPTCHA or fake-error pages that trick them into pasting an attacker-supplied command into the Windows Run dialog, PowerShell, or Windows Terminal, which then downloads the legitimate Node.js installer from official sources before dropping and executing a malicious .js/.node payload. Persistence is established via HKCU Run-key registry entries executing conhost.exe with node.exe headlessly, and via services and scheduled tasks that re-launch PowerShell downloader stages at logon.
The campaign is not a single actor's work: Symantec observed the technique used opportunistically across intrusions of differing sophistication, from commodity infostealer deployment (AsukaStealer) to structured intrusions preceding ransomware. A notable thread ties several intrusions to Woodgnat (also tracked as KongTuke, 404 TDS, Chaya_002, LandUpdate808, TAG-124), a financially motivated initial-access broker active since May 2024 that sells durable enterprise footholds to ransomware affiliates including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. Woodgnat is assessed to possibly be the developer of the Python-based ModeloRAT and is linked to the stealthy, memory-resident Backdoor.Mistic, which DLL-sideloads through the legitimate Microsoft endpoint-security binary MpExtMs.exe while masquerading as "EndpointDlp.dll."
A distinguishing C2 innovation observed in this campaign cluster is EtherHiding: malware (EtherRAT, and reportedly variants of AsukaStealer) retrieves C2 configuration -- URL, port, and encryption key -- from Ethereum smart contracts via public RPC gateways (eth.llamarpc.com, mainnet.gateway.tenderly.co), giving the operators censorship-resistant infrastructure with no attacker-controlled resolver to seize. Separately, the Rust-based C2Looper backdoor (documented by Zscaler ThreatLabz and observed being staged in one Node.js-LOTL fintech intrusion as the final payload) evolved from raw HTTP POST beaconing to a version that stores commands and exfiltrated data as JSON files inside per-victim GitHub repository paths, again abusing a trusted, allow-listed web service to blend C2 traffic into normal developer/CI network noise. The actors additionally abuse Cloudflare Workers (serverless subdomains such as microsoft.desereyunton.workers.dev) and domains spoofing legitimate companies (e.g., a fake Devmine and fake database-services brand) for staging and redirection.
Post-compromise activity documented across the linked intrusions includes native Windows network- and domain-reconnaissance utilities (Net, Netstat, Netsh, Nltest, Arp, Adsisearcher, and Kerberos-ticket-oriented scripts), credential theft via a fake lock-screen overlay, software/asset inventory via PDQInventory, and staged data exfiltration using Curl, Tar, and Bitsadmin. In the tracked fintech case, initial ClickFix-driven PowerShell activity and failed attempts to deploy AdaptixC2 and Cobalt Strike preceded a successful Node.js-based implant (using a native addon, evasion.node) that established registry persistence and ultimately staged the C2Looper Rust backdoor -- consistent with Woodgnat's pattern of selling access forward to ransomware operators.
Target sectors: government administration, finance, hospitality, insurance, education, informationtechnology, professionalservices
Target regions: Asia, North America
Timeline
- Woodgnat (KongTuke) initial-access-broker operation assessed as active since at least May 2024, selling durable enterprise footholds to ransomware affiliates
- Node.js LOTL technique revival begins; wave of intrusions abusing signed node.exe to execute malicious JavaScript observed since February 2026
- Microsoft Defender Experts identify a widespread ClickFix campaign leveraging Windows Terminal (Win+X -> I) as the execution mechanism
- An Asian technology company is compromised via the Node.js LOTL technique
- Attacker-directed download of the official Node.js installer observed as part of the intrusion chain
- Backdoor.Mistic first observed in cybercrime intrusions, deployed via DLL side-loading of MpExtMs.exe
- A Node.js-packaged variant of AsukaStealer first observed in the wild
- Initial ClickFix-driven activity begins against a U.S. fintech company, including failed attempts to deploy AdaptixC2 and Cobalt Strike
- Node.js JavaScript implant (using native addon evasion.node) executed and registry Run-key persistence established in the fintech intrusion
- Symantec/Broadcom Threat Hunter Team publishes Backdoor.Mistic / ModeloRAT report, first tying the activity to Woodgnat/KongTuke
- Multiple outlets (The Hacker News, BleepingComputer, The Register, HelpNetSecurity, SecurityAffairs) report on the Mistic-KongTuke link and its ransomware-broker implications
- C2Looper Rust backdoor staged as a final payload in the fintech intrusion following repeated failed deployment attempts and blockchain-based C2 communications
Detections & IOCs
As of 2026-09-03, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1588, T1204, T1059, T1547, T1053, T1127, T1574, T1055, T1036