{"id":11704,"date":"2026-03-25T13:12:04","date_gmt":"2026-03-25T13:12:04","guid":{"rendered":"https:\/\/events.aavar.org\/avar2025\/?page_id=11704"},"modified":"2026-03-25T13:12:05","modified_gmt":"2026-03-25T13:12:05","slug":"modern-fileless-rat-tactics-node-js-abuse-technical-analysis-and-threat-attribution","status":"publish","type":"page","link":"https:\/\/events.aavar.org\/avar2025\/index.php\/modern-fileless-rat-tactics-node-js-abuse-technical-analysis-and-threat-attribution\/","title":{"rendered":"Modern Fileless RAT Tactics: Node.js Abuse : Technical Analysis and Threat Attribution"},"content":{"rendered":"\n[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column]\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div style=\"height:200px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"banner-text has-x-large-font-size wp-block-paragraph\">AGENDA<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><\/div>\n<\/div>\n\n\n\n<p>[\/vc_column] [\/vc_row]<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"agenda-link wp-block-paragraph\"><strong><a href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/agenda\/\">&lt;&#8212; Back<\/a><\/strong><\/p>\n\n\n\n<p class=\"agenda-heading wp-block-paragraph\">Modern Fileless RAT Tactics: Node.js Abuse : Technical Analysis and Threat Attribution<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This presentation explores a modern threat that leverages Node.js to operate entirely in memory, bypassing traditional endpoint protections. The malware analyzed is a fileless remote access trojan written in JavaScript, designed to evade detection and provide persistent control over compromised systems. Delivered through socially engineered lures, such as fake job interview processes and CAPTCHA forms, this malware reflects tradecraft frequently linked to North Korean state-sponsored groups.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once deployed, the RAT establishes communication with a command-and-control server using XOR-obfuscated and compressed HTTP traffic. It supports advanced features such as SOCKS5 proxy tunneling and is equipped with anti-analysis mechanisms, including virtual machine detection to avoid sandbox environments. These characteristics allow it to remain hidden in enterprise environments while enabling adversaries to maintain long-term access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To fully understand its behavior and control mechanisms, we reconstructed and operated a replica of the command-and-control infrastructure. This reverse engineering effort revealed the malware\u2019s operational commands, communication patterns, and the level of control it grants to attackers. Our findings indicate a broader trend in the adoption of Node.js for malware development, due to its flexibility, cross-platform capabilities, and lower detection footprint.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This session will detail the technical architecture of the malware, walk through the infection chain, and share behavioral patterns useful for detection. We will also map the observed tactics to threat actor activity, presenting strong links to campaigns attributed to the Lazarus group. The talk includes detection strategies, YARA rules, and endpoint artifacts for defenders to use in their environments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attendees will leave with a deeper understanding of emerging JavaScript-based threats, attacker tooling evolution, and practical insights for threat hunting and incident response in enterprise networks.<\/p>\n\n\n\n<div style=\"height:42px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Reegun-Richard-Jayapaul.jpg\" alt=\"\" class=\"wp-image-11705\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Reegun-Richard-Jayapaul.jpg 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Reegun-Richard-Jayapaul-300x300.jpg 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Reegun-Richard-Jayapaul-150x150.jpg 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Reegun-Richard-Jayapaul-200x200.jpg 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong><strong>Reegun Richard Jayapaul<\/strong><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Director of Threat Research at Cyderes with over 14 years of experience in threat research, malware analysis, reverse engineering, incident response, and offensive security. I build solutions to help organizations defend against evolving cyber threats.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">My team regularly publishes new research and contributes to the broader security community. I\u2019m an active contributor to the LOLBAS project, documenting how attackers abuse legitimate binaries to bypass security controls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I&#8217;ve reported critical vulnerabilities, including a remote code execution flaw in Microsoft Teams, and led investigations into major malware campaigns such as GoldenSpy and GoldenHelper. I use threat intelligence to shape proactive defense strategies and improve detection capabilities.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column] AGENDA [\/vc_column] [\/vc_row] &lt;&#8212; Back Modern Fileless RAT Tactics: Node.js Abuse : Technical Analysis and Threat Attribution This presentation explores a modern threat that leverages Node.js to operate entirely in memory, bypassing traditional endpoint protections. The malware analyzed is a fileless remote access trojan written in JavaScript, designed to evade detection and provide persistent control<\/p>\n<div class=\"h10\"><\/div>\n<p><a class=\"more-link2\" href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/modern-fileless-rat-tactics-node-js-abuse-technical-analysis-and-threat-attribution\/\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-11704","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11704","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/comments?post=11704"}],"version-history":[{"count":1,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11704\/revisions"}],"predecessor-version":[{"id":11706,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11704\/revisions\/11706"}],"wp:attachment":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/media?parent=11704"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}