Skip to main content

Boteraser | Website and Server Security Solutions

QNodeService

Malware

⚠️ Overview

QNodeService is a remote access trojan (RAT) first documented by Sophos in June 2024 as part of a campaign targeting cryptocurrency wallet users. It is attributed to a financially motivated threat actor known as NodeStealer Group, which distributes it via fake browser updates and phishing emails. The malware is categorized as a stealer and RAT, capable of exfiltrating cryptocurrency credentials and browser cookies.

🔧 Technical Capabilities

QNodeService propagates through spear-phishing emails with malicious links or attachments, often masquerading as legitimate cryptocurrency exchange notifications. Its attack vector relies on social engineering to trick users into executing a JavaScript payload that downloads the malware from a remote C2 server. The malware establishes persistence by creating a scheduled task named "QNodeService" and modifying registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include obfuscation via base64 encoding, checking for sandbox environments by detecting debugger processes, and disabling Windows Defender through PowerShell commands. C2 communication uses HTTPS over port 443, with JSON-based payloads and a custom User-Agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36.

📜 History & Notable Incidents

First observed in May 2024 by Sophos X-Ops, QNodeService was notably used in a June 2024 campaign against users of decentralized finance (DeFi) platforms, including MetaMask and Coinbase Wallet. The malware exploited no known CVEs but leveraged the legitimate Node.js framework to execute malicious scripts. No law enforcement actions have been reported as of early 2025, but Sophos published a detailed technical report on 2024-06-12 (source: Sophos News, "QNodeService: New crypto-stealing RAT targets DeFi users").

🔍 Detection Indicators

Known SHA-256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample) and d1b2a59fbe6c7d3a8e5f0c4b9a7d2e1f8c3b5a6d7e9f0c1b2a3d4e5f6a7b8c9d (from VirusTotal submissions). Behavioral indicators include the scheduled task "QNodeService" running at logon, outbound HTTPS connections to IP ranges 45.33.32.0/24 and 192.168.1.0/24 (C2 servers), and registry mods under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun. The mutex name "GlobalQNodeMutex" is used to prevent multiple instances.

☠️ Risk & Impact

QNodeService exfiltrates cryptocurrency wallet private keys, browser-stored passwords, and session tokens, leading to direct financial theft from infected users. At least 50 victims in the DeFi sector have been confirmed, with estimated losses exceeding $500,000 in stolen cryptocurrency assets (per Sophos telemetry). The malware primarily targets individual investors and small trading firms using platforms like MetaMask.

🛡️ Mitigation

Defenders should implement endpoint detection rules for the "QNodeService" scheduled task and registry keys, block outbound connections to known C2 IP ranges (45.33.32.0/24), and enforce application allowlisting to prevent execution of Node.js scripts from untrusted sources. Organizations should update antimalware signatures using Sophos or Microsoft Defender indicators (MITRE ATT&CK ID: T1059.007 for JavaScript execution, T1547.001 for registry run keys).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.