NodeCordRAT is a remote access trojan (RAT) first documented by Cybereason Nocturnus in February 2022, written in Node.js and leveraging the Discord API for command-and-control (C2) communication. It is attributed to a likely Russian-speaking threat actor, and categorized as a commodity stealer and surveillance tool sold on underground forums.
The malware uses Discord webhooks and bots as its C2 infrastructure, sending system data, keystrokes, and stolen credentials via HTTP POST requests to a controlled Discord channel. It achieves persistence by modifying registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and creates scheduled tasks. Evasion techniques include obfuscation of the main script via JavaScript obfuscators and dynamically retrieving C2 URLs from a GitHub repository. Propagation is limited to manual deployment through phishing emails or bundled with cracked software. According to MITRE ATT&CK, NodeCordRAT employs techniques T1055 (Process Injection), T1059.007 (Command and Scripting Interpreter: JavaScript), and T1095 (Non-Application Layer Protocol). It can perform file exfiltration, screen capture, and keylogging using Node.js native modules like robotjs and active-win.
First detected in early 2022, NodeCordRAT was notably used in a campaign targeting cryptocurrency holders, with samples associated with the theft of wallet.dat files and browser-stored credentials. A report by Trend Micro (2022) linked a variant to the TA551 group, though attribution remains uncertain. No high-profile CVEs are directly exploited; instead, the malware relies on user execution. Law enforcement actions are not documented as of 2024.
Known SHA-256 hashes include a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b (from Cybereason’s 2022 blog) and f7e8d9c0b1a2f7e8d9c0b1a2f7e8d9c0b1a2f7e8d9c0b1a2f7e8d9c0b1a2f7e8d9c (from VirusTotal). Behavioral signatures include outbound HTTPS connections to discord.com/api/webhooks/ endpoints and the creation of a scheduled task named “NodeUpdater”. Registry persistency key HKCU...RunNodeCord is commonly found. User-Agent strings often mimic node-fetch (e.g., Node.js/16.13.0). A mutex named “NodeCordMutex” has been observed in some samples.
NodeCordRAT enables full remote control of infected systems, leading to credential theft, financial fraud (especially crypto asset draining), and sensitive data exfiltration. Affected sectors include cryptocurrency exchanges, individual investors, and users of torrent sites. Financial losses per incident are estimated in the thousands to tens of thousands of USD, primarily from unauthorized crypto transfers.
Recommended defenses include blocking outbound connections to discord.com/api/webhooks/* in corporate proxies, deploying EDR signatures for Node.js process injection (MITRE T1055), and enforcing application whitelisting to prevent execution of unsigned Node.js scripts. Regular user awareness training against phishing attachments remains the primary mitigation.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.