
Threat actors misuse Node.js to deliver malware and other malicious payloads
Since October 2024, threat actors have been leveraging Node.js to deliver malware and payloads for information theft and data exfiltration. A recent malvertising campaign uses cryptocurrency trading themes to lure users into downloading malicious installers. The attack chain includes initial access, persistence, defense evasion, data collection, and payload delivery. The malware gathers system information, sets up scheduled tasks, and uses PowerShell for various malicious activities. Another emerging technique involves inline JavaScript execution through Node.js. Recommendations include educating users, monitoring Node.js execution, enforcing PowerShell logging, and implementing endpoint protection.
Pulse ID: 67fec5ac1e94a608250d9aa2
Pulse Link: https://otx.alienvault.com/pulse/67fec5ac1e94a608250d9aa2
Pulse Author: AlienVault
Created: 2025-04-15 20:46:36
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
We've seen a high level of events being blocked in #Venezuela recently, including a domain belonging to the #Omnatour #Malvertising Network, which we wrote about last month: https://www.quad9.net/news/blog/trends-h2-2024-cyber-insights
Would love to hear from the community on what you might be seeing.
@SecurityWriter #Malvertising is a real problem and #AdBlocjing is an act of #SelfDefense and #MutualDefense against #Malware!
Dragon Hacks: Slay Browser Ads
https://firewallsdontstopdragons.com/dragon-hacks-slay-browser-ads/
A large-scale malvertising campaign using GitHub as a primary attack vector has infected nearly one million devices worldwide, Microsoft has revealed.
https://www.computing.co.uk/news/2025/security/github-hosted-malware-infects-a-million-devices
Microsoft has taken down an undisclosed number of GitHub repositories used in a massive #malvertising campaign that impacted almost one million devices worldwide #cybercrime
Microsoft Uncovers Malvertising Campaign Affecting 1 Million PCs: A Deep Dive into the Attack
A recent report from Microsoft reveals a sophisticated malvertising campaign that has compromised nearly one million devices globally. This article explores the technical intricacies of the attack, it...
Smashing Security podcast #407: HP’s hold music, and human trafficking - Journey with us to Myanmar's shadowy scam factories, where trafficked workers are forced ... https://grahamcluley.com/smashing-security-podcast-407/ #technicalsupportscam #romancebaiting #malvertising #lawℴ #malware #podcast #myanmar #printer #scam #hp
#Meanwhile...
#WhateverHappenedTo: #vmst.io...
#OhYeah... #ShadowBan(s) and #ReplyGuys; because of all the #Malvertising...
#YouKnow what "they/them" should do...
#MakeMoreHashtags and #TheFediverseRemembers... With #TheRightStaff
|
Our latest Cyber Insights for H2 2024 is live!
https://www.quad9.net/news/blog/trends-h2-2024-cyber-insights
Have you ever wondered what happens if you say yes to every request to receive push notifications from sketchy websites?
For the past few months we have done exactly that, exposing an old phone to an endless barrage of scareware and malicious ads.
Find out more here: https://blogs.infoblox.com/threat-intelligence/pushed-down-the-rabbit-hole/
#dns #threatintel #adtech #adware #malware #scam #phishing #cybercrime #cybersecurity #vextrio #infoblox #infobloxthreatintel #malvertising #tds
Cricket and Matt asked me to join them for the Ask Mr DNS podcast last week. It's a great show that i've listened to for years.
We talked about securing networks by blocking bad things in DNS and how our research group @InfobloxThreatIntel does that work. I talk a bit about malicious adtech like #VexTrio ....
This whole show is completely unrehearsed and i had no real idea what we were going to cover lol... so fingers crossed it makes sense to folks.
There are some great episodes about the Dyn attacks in 2015 that you should listen to if you have an interest in DDOS attacks.
#threatintel #dns #cybercrime #cybersecurity #infosec #infoblox #phishing #malware #malvertising
@carnage4life Pretty shure advertisers are pissed if Google decides to inflate the playback numbers that way...
El lado del mal - Fake Brokers y Melendi en los anuncios de los ciberestafadores en Internet https://www.elladodelmal.com/2025/01/fake-brokers-y-melendi-en-los-anuncios.html #fakebrokers #ciberestafa #criptomonedas #phishing #fakenews #BitCoin #Twitter #X #Malvertising