Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: defense-evasion (2 articles)Clear

Attackers abuse the trusted Node.js runtime to run malware past defenses

Symantec reported that threat actors are abusing the legitimate, digitally signed Node.js runtime to run malicious JavaScript while slipping past security tools, in attacks on government, technology, and hospitality targets since February. Because the Node.js executable is a trusted developer tool, defenses rarely flag it, so instead of dropping a malicious program the attackers stage the genuine runtime and keep their harmful logic in interpreted scripts. They gain persistence through a Windows registry startup key and, in one case, pulled command-and-control instructions from the blockchain using a technique called EtherHiding. The activity has been tied to a ClickFix social-engineering entry point and an initial-access broker.

Check
Hunt for unexpected Node.js installations on machines that should not run developer tools, suspicious registry startup entries invoking the runtime, and outbound traffic to blockchain endpoints used for command and control.
Affected
Windows environments where a signed Node.js runtime can be introduced and run scripts unnoticed; attackers use it to execute malicious JavaScript, persist through registry keys, and evade tools that trust the binary.
Fix
Apply application control to restrict where the Node.js runtime may run, alert on its use outside development, monitor script execution and registry run-key changes, and block known blockchain command-and-control and ClickFix infrastructure.

GodDamn ransomware uses a Microsoft-signed malicious driver to disable defenses

Symantec detailed GodDamn, a ransomware operation that disables endpoint defenses using PoisonX, a malicious kernel driver its developers managed to get signed by Microsoft, an unusual escalation over the more common tactic of abusing a legitimate vulnerable driver. In an early-June attack, the operators used AnyDesk for remote access and a credential-harvesting toolkit that pulls passwords from browsers, Windows Credential Manager, cached domain credentials, email clients, and network traffic, before deploying the ransomware. Alongside the signed driver, they ran a user-mode tool disguised as a Symantec product to blind security software. Symantec links GodDamn to a developer it tracks as Hyadina and says the group is actively improving its defense-evasion capabilities.

Check
Watch for bring-your-own-driver activity and processes masquerading as security products, audit remote-access tools like AnyDesk in your environment, and monitor for credential-harvesting across browsers and Windows credential stores.
Affected
Windows organizations where attackers gain a foothold; GodDamn uses a Microsoft-signed malicious driver to switch off endpoint defenses, harvests credentials broadly, then encrypts systems, making detection before deployment much harder.
Fix
Enable driver block lists and tamper protection, restrict who can load kernel drivers, tightly control remote-access software, enforce phishing-resistant MFA, and keep monitored offline backups so encryption stays recoverable.