Back to Intelligence

Node.js LOLBin Abuse, PaperCut MF Zero-Days & AI-Orchestrated Intrusions: AdaptixC2, AsukaStealer, GLUTTON OTX Pulse Analysis — Enterprise Detection Pack

SA
Security Arsenal Team
October 3, 2026
11 min read

Three concurrent OTX pulses paint a consistent picture: initial access brokers and state-adjacent operators are industrializing credential theft and foothold establishment against government, education, technology, and finance targets — with a pronounced focus on the United States and Asia-Pacific. The common thread across all three campaigns is the abuse of trusted, signed binaries and AI-augmented tooling to bypass signature-based controls and harvest credentials at scale.

Pulse 1 — Woodgnat / Node.js resurgence: Since February 2026, the actor tracked as Woodgnat has revived Node.js LOLBin abuse, pairing the legitimate signed node.exe with the ClickFix social-engineering technique to execute malicious JavaScript payloads. Post-exploitation tooling includes ModeloRAT, AsukaStealer, EtherRAT, C2Looper, Backdoor.Mistic, and dual C2 frameworks — Cobalt Strike Beacon and AdaptixC2. The "EtherHiding" tag indicates blockchain-based C2 dead-dropping (BNB Smart Chain contract storage), making infrastructure takedown-resistant. Woodgnat operates as a ransomware access broker — the credentials and access harvested here will be sold or handed to ransomware affiliates.

Pulse 2 — PaperCut MF zero-day intrusion: On August 31, 2026, actors exploited CVE-2026-82078 and CVE-2026-81578 against an internet-facing PaperCut MF 24.0.2 print server in the education sector. The chain: in-memory Java loader → web shell → trojanized Microsoft Copilot binary carrying AdaptixC2, followed by credential dumping and lateral movement. Two additional CVEs (CVE-2026-88771, CVE-2026-88772) appear in the indicator set, suggesting the exploit kit covers a broader PaperCut attack surface than the public writeup.

Pulse 3 — AI-orchestrated intrusions (SecFlow/GLUTTON): A Chinese-speaking operator deployed the SecFlow AI orchestration framework, using commercial LLMs (Claude, Qwen, DeepSeek) as operational components for reconnaissance, exploit selection, and data collection across Taiwan, Indonesia, China, Vietnam, and Afghanistan. The framework detonates SecBox payloads and GLUTTON web shells with steganographic payload delivery. Notably, the CVE arsenal is legacy — Shellshock (CVE-2014-6271), Log4Shell (CVE-2021-44228), Spring4Shell (CVE-2022-22965), Ghostcat (CVE-2020-1938) — indicating AI agents are being used to mass-exploit known but unpatched infrastructure rather than burn zero-days.

Collective objective: credential harvesting, persistent access, and resale. Organizations should treat any detection of these chains as a pre-ransomware event.


Threat Actor / Malware Profile

Woodgnat (Ransomware Access Broker)

  • Distribution: ClickFix-style social engineering — victims are lured to fake human-verification pages (challenge-refernow.com, csa-humanchecknow.com, mail.authorized-logins.net) and instructed to paste malicious commands that invoke Node.js.
  • Payload behavior: The signed node.exe binary executes attacker-supplied JavaScript, staging AsukaStealer (credential/cookie/wallet theft), ModeloRAT, and EtherRAT.
  • C2: Dual-framework redundancy — Cobalt Strike Beacon for interactive access, AdaptixC2 as fallback. EtherHiding: C2 addresses and payloads stored in blockchain smart contracts (note mainnet.gateway.tenderly.co, an Ethereum RPC gateway, in the IOC set — a strong EtherHiding tell).
  • Persistence: Scheduled tasks and registry Run keys created via Node child-process execution.
  • Anti-analysis: Living-off-the-land signed binary execution defeats signature AV; blockchain C2 defeats domain takedowns and reputation filtering.

AdaptixC2 (Post-Exploitation Framework — Pulses 1 & 2)

  • Distribution: Dropped via web shell in the PaperCut intrusion, packaged inside a trojanized Microsoft Copilot binary — abusing user trust in AI-branded software.
  • Payload behavior: In-memory .NET/Reflective loader via Java web shell; supports credential dumping (LSASS), token theft, SOCKS pivoting, and lateral movement.
  • C2: HTTP(S) beaconing with configurable jitter; observed infrastructure includes 156.227.0.13.
  • Anti-analysis: In-memory-only Java loader leaves minimal disk artifacts; trojanized signed-appearing binaries evade allowlists.

SecFlow / SecBox / GLUTTON (AI-Orchestrated Intrusion Set)

  • Distribution: AI agents autonomously scan for and exploit legacy CVEs (Shellshock, Log4Shell, Spring4Shell, Struts2 CVE-2016-4438-class, Alibaba Nacos CVE-2021-29441, Grafana CVE-2021-43798).
  • Payload behavior: GLUTTON web shells deployed on compromised Java/PHP servers; SecBox for post-exploitation; steganographic payloads (malware embedded in images) to evade content inspection.
  • C2: Web shell traffic blends into legitimate HTTP; IOC wscript.shell.run indicates Windows-side stagers using WScript COM instantiation.
  • Persistence: Web shells on internet-facing servers provide durable, credential-independent access.
  • Anti-analysis: LLM-driven adaptive exploitation mutates request patterns per target; steganography defeats file-type-based detection.

IOC Analysis

The indicator set spans five types, each requiring different operationalization:

TypeExamplesSOC Action
Domainsmueleer.com, grande-luna.top, challenge-refernow.com, csa-humanchecknow.comBlock at DNS sinkhole / secure web gateway. These are ClickFix lure and C2 domains. Query DNS logs retroactively 90 days.
Hostnamesmainnet.gateway.tenderly.co, mail.authorized-logins.nettenderly.co is a legitimate blockchain RPC service — do not bulk-block; instead alert on non-developer endpoints communicating with blockchain RPC gateways (EtherHiding indicator).
IPv4156.227.0.13Block at perimeter; hunt NetFlow/proxy logs for beaconing (regular-interval connections, low-and-slow jitter).
SHA256 hashesd2e55213…, cf6dd15b…, bc5fd75b…Push to EDR blocklists; retro-hunt file creation events. Hashes are brittle — pair with behavioral rules below.
CVEsCVE-2026-82078/81578 (PaperCut), CVE-2021-44228, CVE-2022-22965, CVE-2014-6271Feed to vuln scanner as priority patch set. PaperCut MF ≤ 24.0.2 must be patched or isolated immediately. Legacy CVEs indicate scanner coverage gaps — if these are exploitable in your estate, your patch SLA is failing.

Tooling: Decode EtherHiding transactions via BscScan/Etherscan contract storage inspection; pivot on AdaptixC2 TLS JA3/JA4 fingerprints in Zeek/Suricata; use YARA against the Java loader's in-memory class patterns. The wscript.shell.run string IOC should be treated as a behavioral detection pivot, not a network IOC.


Detection Engineering

YAML
---
title: Node.js LOLBin Execution of Remote or Script-Based Payload (Woodgnat / ClickFix)
id: 9f3c2a71-4b6e-4d1a-9c5f-2e8a7b1d3f01
status: experimental
description: Detects the legitimate signed node.exe executing inline JavaScript, spawning child processes, or being executed from user-writable/temp paths — consistent with ClickFix-delivered AsukaStealer/ModeloRAT staging.
author: Security Arsenal Threat Intelligence
logsource:
  category: process_creation
  product: windows
detection:
  selection_binary:
    Image|endswith: '\node.exe'
  selection_suspicious:
    CommandLine|contains:
      - '-e '
      - '--eval'
      - 'child_process'
      - 'Invoke-WebRequest'
      - 'curl '
      - 'certutil'
      - 'mshta'
  selection_path:
    Image|contains:
      - '\AppData\Local\Temp\'
      - '\Users\Public\'
      - '\Downloads\'
  condition: selection_binary and (selection_suspicious or selection_path)
falsepositives:
  - Legitimate Node.js development on developer workstations
level: high
tags:
  - attack.execution
  - attack.t1059.007
  - attack.t1218
---
title: PaperCut MF Spawning Suspicious Child Processes (Web Shell / Java Loader)
id: 1a7d4e82-5c3b-4f2a-8d6e-9b1c3a5f7e02
status: experimental
description: Detects PaperCut MF service processes spawning cmd, powershell, wscript, or unexpected java processes — consistent with CVE-2026-82078/81578 exploitation and AdaptixC2 delivery via trojanized Copilot binary.
author: Security Arsenal Threat Intelligence
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|contains:
      - 'pc-app.exe'
      - 'pc-server.exe'
      - '\PaperCut MF\'
  selection_parent_java:
    ParentImage|endswith: '\java.exe'
    ParentCommandLine|contains: 'papercut'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\rundll32.exe'
      - '\regsvr32.exe'
      - '\whoami.exe'
      - '\nltest.exe'
  condition: (selection_parent or selection_parent_java) and selection_child
falsepositives:
  - Rare; legitimate PaperCut admin scripts. Verify against change windows.
level: critical
tags:
  - attack.initial_access
  - attack.t1190
  - attack.t1505.003
---
title: EtherHiding — Blockchain RPC Gateway Access from Non-Developer Endpoints
id: 7b2e9f13-8a4d-4c6b-b2e5-3d9f1a6c8e03
status: experimental
description: Detects network connections to blockchain RPC gateways (Tenderly, Infura, Alchemy, BSC public nodes) from endpoints without developer tooling — consistent with Woodgnat EtherHiding C2 dead-drop resolution.
author: Security Arsenal Threat Intelligence
logsource:
  category: dns
  product: windows
detection:
  selection:
    QueryName|contains:
      - 'gateway.tenderly.co'
      - 'mainnet.infura.io'
      - 'bsc-dataseed'
      - 'rpc.ankr.com'
      - 'eth-mainnet.g.alchemy.com'
  condition: selection
falsepositives:
  - Developer workstations, Web3 QA environments, crypto treasury systems
level: medium
tags:
  - attack.command_and_control
  - attack.t1102.001
KQL — Microsoft Sentinel / Defender
// Hunt: AdaptixC2 / Woodgnat / GLUTTON activity — C2, LOLBin, and web shell behaviors
// Microsoft Sentinel — 14-day lookback
let Lookback = 14d;
let BadDomains = dynamic(["mueleer.com","grande-luna.top","oeannon.com","challenge-refernow.com","csa-humanchecknow.com","mail.authorized-logins.net","www.xt24.com"]);
let BadIP = "156.227.0.13";
let BadHashes = dynamic(["d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222","cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c","bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58"]);
let NetEvents =
    DeviceNetworkEvents
    | where TimeGenerated > ago(Lookback)
    | where RemoteUrl has_any (BadDomains) or RemoteIP == BadIP
    | project TimeGenerated, DeviceName, InitiatingProcessFileName, RemoteIP, RemoteUrl, RemotePort, HuntHit = "Network IOC";
let ProcEvents =
    DeviceProcessEvents
    | where TimeGenerated > ago(Lookback)
    | where
        // Node.js LOLBin abuse
        (FileName =~ "node.exe" and (ProcessCommandLine has_any ("-e ","--eval","child_process") or FolderPath has_any ("\\Temp\\","\\Public\\","\\Downloads\\")))
        // PaperCut spawning shells
        or (InitiatingProcessFolderPath has "PaperCut" and FileName in~ ("cmd.exe","powershell.exe","wscript.exe","rundll32.exe"))
        // WScript COM stager (SecFlow indicator)
        or (ProcessCommandLine has "wscript.shell" and FileName in~ ("wscript.exe","cscript.exe","powershell.exe"))
        // TrojCopilot-style masquerade: Copilot binary outside expected paths
        or (FileName has "copilot" and not (FolderPath has_any ("\\Program Files\\","\\WindowsApps\\")))
    | project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, SHA256, HuntHit = "Behavioral";
let HashEvents =
    DeviceProcessEvents
    | where TimeGenerated > ago(Lookback)
    | where SHA256 in (BadHashes)
    | project TimeGenerated, DeviceName, FileName, FolderPath, SHA256, HuntHit = "Known Malware Hash";
union NetEvents, ProcEvents, HashEvents
| summarize FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by DeviceName, HuntHit, tostring(RemoteUrl), tostring(RemoteIP), tostring(FileName), tostring(SHA256)
| order by LastSeen desc
PowerShell
<#
.SYNOPSIS
  IOC Hunt — Woodgnat Node.js abuse, AdaptixC2, GLUTTON web shell artifacts
.DESCRIPTION
  Checks for malicious ClickFix lure artifacts, Node.js persistence, AdaptixC2 IOCs,
  and EtherHiding network connections. Run elevated. Output: JSON per host.
#>

$ErrorActionPreference = 'SilentlyContinue'
$Findings = @()

# --- 1. Known malicious domains/IP in DNS cache ---
$badIOCs = @('mueleer.com','grande-luna.top','oeannon.com','challenge-refernow.com',
             'csa-humanchecknow.com','authorized-logins.net','xt24.com','156.227.0.13')
$dnsCache = Get-DnsClientCache | Where-Object { $e = $_.Entry; $badIOCs | Where-Object { $e -like "*$_*" } }
foreach ($d in $dnsCache) {
    $Findings += [PSCustomObject]@{Type='DNSCache'; Indicator=$d.Entry; Detail=$d.Data; Severity='Critical'}
}

# --- 2. Active connections to AdaptixC2 IP / blockchain RPC (EtherHiding) ---
$conns = Get-NetTCPConnection -State Established |
    Where-Object { $_.RemoteAddress -eq '156.227.0.13' -or $_.RemotePort -in @(443,8443) } |
    ForEach-Object {
        $p = Get-Process -Id $_.OwningProcess
        [PSCustomObject]@{Type='NetConn'; Indicator=$_.RemoteAddress; Detail="$($p.ProcessName) ($($p.Path)):$($_.RemotePort)"; Severity=$(if($_.RemoteAddress -eq '156.227.0.13'){'Critical'}elseif($p.ProcessName -in @('node','wscript','java','powershell')){'High'}else{'Info'})}
    }
$Findings += $conns | Where-Object { $_.Severity -ne 'Info' }

# --- 3. Node.exe running from suspicious paths ---
Get-Process node -ErrorAction SilentlyContinue | Where-Object {
    $_.Path -match 'Temp|Public|Downloads|AppData\\Local\\(?!Programs)'
} | ForEach-Object {
    $Findings += [PSCustomObject]@{Type='SuspiciousNode'; Indicator=$_.Path; Detail="PID $($_.Id)"; Severity='High'}
}

# --- 4. Persistence: Run keys & scheduled tasks invoking node/wscript/mshta ---
$runKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run',
             'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run')
foreach ($key in $runKeys) {
    (Get-ItemProperty $key).PSObject.Properties | Where-Object {
        $_.Value -match 'node\.exe|wscript|mshta|javascript:'
    } | ForEach-Object {
        $Findings += [PSCustomObject]@{Type='RunKey'; Indicator=$_.Name; Detail=$_.Value; Severity='High'}
    }
}
Get-ScheduledTask | Where-Object {
    $_.Actions.Execute -match 'node\.exe|wscript\.exe|mshta\.exe' -or
    $_.Actions.Arguments -match '-e |--eval|http'
} | ForEach-Object {
    $Findings += [PSCustomObject]@{Type='ScheduledTask'; Indicator=$_.TaskName; Detail="$($_.Actions.Execute) $($_.Actions.Arguments)"; Severity='High'}
}

# --- 5. Known malware hashes on disk (PaperCut AdaptixC2 loaders) ---
$badHashes = @('d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222',
               'cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c',
               'bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58')
$scanPaths = @("$env:TEMP","$env:PUBLIC","$env:ProgramData","$env:USERPROFILE\Downloads")
foreach ($path in $scanPaths) {
    Get-ChildItem $path -Recurse -File -Include *.exe,*.dll,*.js,*.jar -ErrorAction SilentlyContinue |
        ForEach-Object {
            $h = (Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower()
            if ($badHashes -contains $h) {
                $Findings += [PSCustomObject]@{Type='MalwareHash'; Indicator=$_.FullName; Detail=$h; Severity='Critical'}
            }
        }
}

# --- 6. Trojanized Copilot binary outside expected install paths ---
Get-ChildItem "C:\Users" -Recurse -Filter "*copilot*.exe" -ErrorAction SilentlyContinue |
    Where-Object { $_.FullName -notmatch 'Program Files|WindowsApps' } |
    ForEach-Object {
        $Findings += [PSCustomObject]@{Type='Masquerade'; Indicator=$_.FullName; Detail=(Get-FileHash $_.FullName).Hash; Severity='High'}
    }

# --- Output ---
if ($Findings.Count -gt 0) {
    $Findings | Sort-Object Severity | ConvertTo-Json -Depth 4
    Write-Host "[!] $($Findings.Count) findings on $env:COMPUTERNAME — escalate to IR" -ForegroundColor Red
} else {
    Write-Host "[+] No Woodgnat/AdaptixC2/GLUTTON indicators found on $env:COMPUTERNAME" -ForegroundColor Green
}

Response Priorities

Immediate (0–4 hours)

  • Block all domains, the IPv4 156.227.0.13, and the three SHA256 hashes at EDR, DNS, and web gateway layers. Allowlist-only blockchain RPC gateways (Tenderly/Infura/Alchemy/BSC) — alert on any endpoint outside approved developer segments.
  • Isolate all internet-facing PaperCut MF servers ≤ version 24.0.2. CVE-2026-82078/81578 are actively exploited zero-days. If patching is unavailable, place behind VPN or take offline.
  • Deploy the Sigma rules and run the KQL hunt across a 14–30 day lookback. Any PaperCut process spawning a shell is a critical incident until disproven.

24 Hours

  • Credential reset at scale: AsukaStealer and AdaptixC2 credential-dumping mean any host with a confirmed hit has compromised credentials. Force resets for all users who authenticated from affected endpoints, revoke session tokens and browser cookies (infostealers exfiltrate live session material), and rotate service accounts used on PaperCut servers.
  • Audit for accounts created or OAuth consents granted in the exposure window — access brokers sell persistence, not just passwords.
  • Verify MFA coverage; check MFA fatigue/anomalous push events for targeted users in gov/edu/finance segments.

1 Week

  • Application control: Constrain node.exe via WDAC/AppLocker to signed development paths only; alert on execution from user-writable directories. There is near-zero legitimate business need for Node.js outside developer fleets.
  • Patch legacy attack surface: The SecFlow pulse proves AI agents are mass-exploiting Shellshock, Log4Shell, and Spring4Shell at scale. Run an authenticated scan for the full CVE list and remediate — these are 2014–2022 vulnerabilities and their presence is a patch-governance failure.
  • ClickFix user training: Brief helpdesk and end users on fake "verify you're human" pages that instruct pasting commands — this social-engineering pattern is Woodgnat's primary initial-access vector.
  • Segment print infrastructure; PaperCut servers should never be directly internet-facing.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.