Advisory
Published 2026-09-03
Verified 2026-09-19

Symantec: attackers abuse signed Node.js runtime to run interpreted malware

The Hacker News (3 September 2026) summarises a Symantec Threat Hunter Team report: since February 2026, operators have abused the legitimate, signed node.exe runtime to execute malicious JavaScript rather than dropping unsigned binaries, with registry Run-key persistence, against government, technology and hotel targets. One Asian technology company intrusion (March–July 2026) installed official Node.js from nodejs.org after ClickFix access, then used EtherHiding-style retrieval after AdaptixC2/Cobalt Strike beacons were blocked. Related tooling includes ModeloRAT, Mistic/MLTBackdoor (KongTuke/Woodgnat), GateKeeper, NexShield Chrome extension, and C2Looper against a U.S. fintech. Prefer application-control policies that constrain node.exe outside developer workstations; hunt for unexpected node.exe + Run keys and EtherHiding beacons.

Exploited in Australia?
unknown

Primary: The Hacker News (3 Sep 2026) · Vendor: Symantec / Broadcom Security (report summarised by THN)

tech identity