
Hackers Abuse Legitimate Node.js Runtime to Hide Persistent Backdoor in Enterprise Attacks
Attackers persuade employees to accept a remote-control request during screen sharing or to open Quick Assist and provide its access code. Once inside, they use legitimate remote management and support tools to control the device. They then run PowerShell to download a malicious MSI package from cloud storage and install it silently with Windows Installer. […]
The post Hackers Abuse Legitimate Node.js Runtime to Hide Persistent Backdoor in Enterprise Attacks appeared first on Cyber Security News.