Nodersok is the fileless malware that turns systems into proxies to perform click-fraud

The initial Nodersok Trojan malware campaign is focused on a copy of Node.js that once downloaded and installed, converts systems into proxies. Malware infected thousands of machines over the course of weeks in Europe and the U.S. This primary attack was focused on home users, although organizations and industries like education, businesses, professionals in finance, healthcare, retail also got affected.[2] However, recent reports state that the malware is still active and might get updates, so trojan can attempt to get on machines belonging to any user.
| Name | Nodersok malware |
|---|---|
| Alternate name | Divergent |
| Type | Trojan/ Fileless malware |
| Primary purpose | This malware infects the machine to turn the computer into a proxy that can later run malicious activities an use the device to commit click-fraud by earning money through the infected system. Once malicious HTA files get launched on the system, other multi-staged processes get triggered |
| Possible symptoms | You may encounter suspicious processes running on the machine, files added in the background. General slowness and system freezes also can indicate issues related to malware infections |
| Danger | This virus can open a way to the infected system to potential malware infiltrations or even infect the machine with ransomware and other dangerous malware directly loading a payload dropper |
| Distribution | Malicious files get delivered either with the help of spam email attachments or from software installers, maliciously lased websites that contain the infected components |
| Targets | Home users mainly, but the biggest attack was also initiated on businesses and industries |
| Malicious files | Node.js; Node.exe; MSHTA.exe |
| Elimination | Get professional anti-malware tools that can detect and terminate the machine from various intruders, run other processes including Nodersok malware removal. Rely on FortectIntego for general system cleaning |
Nodersok malware attack starts when an infected file comes to the machine because usually, such infections modify legitimate files, including malicious code. In most cases, these files are macro-infected documents or software installers made by hackers. The virus also takes advantage of system vulnerabilities, and other weaknesses, so direct attacks are successful. This trojan can launch multiple dangerous modules and install threats like cryptocurrency miners and run different tasks or processes in the background.
This Nodersok/ Divergent malware has many modules triggered on different infection stages:
- PowerShell module that disables OS updates, antivirus tools, security functions;
- A binary shellcode tries to perform elevation of privilege;
- A shellcode that runs Windivert packet filtering engine;
- JavaScript module that is written in Node.js framework that turns the machine into a proxy.
Unfortunately, Nodersok Trojan spreads via malicious sites and installs HTA files on the machine that once opened can lead to damage and other serious issues, so it is not intrusive enough to appear on the screen immediately. Although Mac users cannot be affected by this malware, trojan infects most of the devices based on Windows OS.
This fileless virus can relay malicious traffic for nefarious means, so once the Nodersok/ Divergent malware is on the system, earning money using your device for various fraudulent activities becomes the main goal of cybercriminals behind the threat. Two different names are based on different analyses and researches, but malware acts the same and can lead to numerous malware infections if left running on the system. 
Nodersok Trojan is working in the background of your computer and disrupts the usage of the machine this way, but you cannot notice that since it is not invasive. Virus downloads HTA files on the computer before starting the infection process, and then various applications start running malicious scripts injected by the malware.
This is the method used particularly for persistency because using safe and legitimate applications for malicious processes keeps Nodersok malware removal difficult. Anti-malware tools cannot indicate the process or the program as malicious since the app is initially safe. Unfortunately, this malware uses files associated with Windows Defender itself, so it appears especially safe for the system and security tools.
However, although you need to remove Nodersok malware as soon as possible, it is more difficult to spot the infection on time. According to initial versions and sample analysis, this virus is yet to get extremely dangerous, but right now, it is not that notorious of malware. It is possible that trojan is used to proliferate more advanced malware on the machine further once the scrips start running on the device.
It is extremely important to delete the Nodersok Trojan as soon as possible, so the virus doesn't escalate to the even worse stage. However, there are not many symptoms that can be observed by the victim. You may potentially notice some system slowdowns, but this is not that typical when the PC is usually fast. An anti-virus scan is the best method that can show issues and detect malware on the machine. Get FortectIntego or a different tool designed for fighting threats.
Ways to avoid getting infected by malware and virus script delivery methods
This malware involves malicious files and multiple tactics that get used to delivering those infected materials. Malware can rely on security flaws and vulnerabilities that help hackers to spread their products directly on the targeted machine. Pop-ups and banners are mainly associated with intrusive commercial content, but clicking on them can expose you to malicious sites that are laced with malicious scripts or trigger automatic downloads of apps and data.
These are the tips for your behavior online when you want to avoid infiltrations of such malicious trojans:
- Don't click on commercial banners without considering the malware possibility. Experts[3] always note that intrusive ads have more to them besides annoying you.
- Stay cautious when installing programs and applications. Less reliable sites tan include add-ons with security flaws.
- Visit trustworthy sites and stay away from torrent pages.
- Update your security tools and anti-malware protection apps. Malware gets updates and new versions, so your tools should get updated too.
Get rid of any contents that can be associated with Nodersok malware by scanning the PC fully
Typically, Nodersok trojan malware arrives on the system via malicious content injected on websites. That includes advertisements and other material found on suspicious pages, not reputable pages. It is common that banners or push notifications contain the script of this malware.
Once the victim clicks on such content, the virus downloads malicious files, and once those get opened, scripts spread the virus on the device. This is how trojan affects the security of your device, and spreads other malware, exposes the system to vulnerabilities. From there, time is a very important factor for Nodersok malware removal.
The sooner you detect this trojan, the better because you can remove Nodersok malware completely from the machine. When malware lands other files or programs on the device, it makes the initial trojan persistent and more difficult to terminate. Rely on FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes and try tips below to fully clean the machine.
Was this guide helpful?
Be the first to comment