security1 distinct publisher
Symantec finds attackers installing the signed Node.js runtime to run their payloads
The Threat Hunter Team says the technique has hit government departments, technology firms and hotels since February 2026. In one case, the operators moved to node.exe only after their Cobalt Strike beacons kept getting blocked.
Publishers:thehackernews.com
Reality
- Evidence57
- Adoption58
- Hype gap+16
- Incentives66