New #Nodersok #malware has infected thousands of PCs

Thousands of Windows computers across the world have been infected with a new strain of malware that downloads and installs a copy of the Node.js framework to convert infected systems into proxies and perform click-fraud.

The malware, named Nodersok (in a Microsoft report) and Divergent (in a Cisco Talos report), was first spotted over the summer, distributed via malicious ads that forcibly downloaded HTA (HTML application) files on users' computers.

Users who found and ran these HTA files started a multi-stage infection process involving Excel, JavaScript, and PowerShell scripts that eventually downloaded and installed the Nodersok malware.

The malware itself has multiple components, each with its own role. There's a PowerShell module that tries to disable Windows Defender and Windows Update, and there's a component for elevating the malware's permissions to SYSTEM level.

But there are also two components that are legitimate apps -- namely WinDivert and Node.js. The first is an app for capturing and interacting with network packets, while the second is a well-known developer tool for running JavaScript on web servers.

According to Microsoft and Cisco reports, the malware uses the two legitimate apps to start a SOCKS proxy on infected hosts. But here is where the reports diverge. Microsoft claims the malware turns infected hosts into proxies to relay malicious traffic. Cisco, on the other hand, says these proxies are used to perform click-fraud.

Nevertheless, malware is malware, and it's not a good sign when someone gets infected, despite the output. Just like any other malware strain built on a client-server architecture, Nodersok's creators could, at any point, deploy other modules to perform additional tasks, or even deploy secondary malware payloads like ransomware or banking trojans.

Since Microsoft found the malware, Windows Defender should also be able to spot it.

To prevent infections, the best advice is that users not run any HTA files they find on their computers, especially if they don't know the files' precise origin. Files downloaded from a web page out of the blue are always a bad sign and shouldn't be trusted, regardless of extension.

According to Microsoft telemetry, Nodersok has managed to already infect "thousands of machines in the last several weeks." Most of the infections have taken place this month, and have hit US and EU-based users, the company said...

Read more:

wither 3

Vista Guru
Gold Member
I wonder if software like Malwarebytes has been updated yet to detect it. I went to their forum and searched on it but came up empty.


Vista Pro
I wonder if software like Malwarebytes has been updated yet to detect it. I went to their forum and searched on it but came up empty.

Hi wither 3:

See David H. Lipman's post # 2 in the Malwarebytes 3 forum thread Nodersok. I assume that comment only applies to Malwarebytes Premium users with a paid subscription who have the real-time Exploit Protection module enabled. The Malwarebytes Lab blog also posted a 2-part series of articles in late 2018 about how anti-exploit can help mitigate attacks from this type of malware - see Fileless Malware: Getting the Lowdown on This Insidious Threat.
32-bit Vista Home Premium SP2 * Norton Security Deluxe v22.15.2.22 * Malwarebytes Free v3.5.1-1.0.365