Back to Intelligence

Woodgnat Node.js Loader Campaign + PaperCut MF Zero-Day AdaptixC2 Intrusions: OTX Pulse Analysis — Enterprise Detection Pack

SA
Security Arsenal Team
October 3, 2026
9 min read

Two concurrent OTX pulses paint a picture of adversaries increasingly abusing trusted, signed binaries and enterprise software to slip past signature-based defenses. This is not opportunistic noise — it is a deliberate tradecraft shift toward living-off-the-land execution combined with exploitation of internet-facing management platforms.

Pulse 1 — The Node.js Resurgence (attributed to Woodgnat): Since February 2026, researchers have tracked a resurgence of Node.js abuse targeting government departments, technology firms, financial institutions, hospitality, and education — with confirmed targeting of U.S. entities. The attack chain leverages the ClickFix social engineering technique (fake human-verification/"prove you're not a robot" prompts that trick users into executing clipboard-pasted commands) to stage the official, digitally signed node.exe binary, which then executes malicious JavaScript payloads in memory. Because node.exe is a legitimate signed runtime, it bypasses application allowlisting and many signature engines. The malware ecosystem delivered through this chain is extensive: ModeloRAT, EtherRAT, Backdoor.Mistic, AsukaStealer, C2Looper, Cobalt Strike Beacon, and AdaptixC2. Tags referencing "ransomware access broker" strongly suggest Woodgnat operates as an initial access broker (IAB) — building footholds that are later sold to ransomware affiliates. The "EtherHiding" tag indicates blockchain-based payload/C2 staging (Binance Smart Chain / Ethereum smart contracts hosting JavaScript), which explains the presence of mainnet.gateway.tenderly.co in the indicator set.

Pulse 2 — PaperCut MF Zero-Day Intrusion (unattributed): On August 31, 2026, threat actors exploited two zero-days (CVE-2026-82078 and CVE-2026-81578) against an internet-facing PaperCut MF 24.0.2 print server in the Education sector. The intrusion deployed an in-memory Java loader establishing a web shell, through which a trojanized Microsoft Copilot binary containing AdaptixC2 was delivered. Post-compromise activity included credential dumping and lateral movement, culminating in domain-level compromise.

Collective assessment: Both campaigns converge on AdaptixC2 — an emerging open-source C2 framework increasingly replacing Cobalt Strike among mid-tier actors — and both abuse legitimate signed software (node.exe, Copilot binary, Java runtime) as execution vehicles. The objective in both cases is durable access and credential theft, consistent with IAB monetization and pre-ransomware staging.

Threat Actor / Malware Profile

Woodgnat (IAB — Node.js Campaign)

  • Distribution: ClickFix-style social engineering — fake CAPTCHA / "human verification" pages (challenge-refernow.com, csa-humanchecknow.com, mail.authorized-logins.net reflect this lure infrastructure) instruct victims to paste malicious commands that download and execute the legitimate Node.js installer.
  • Payload behavior: Malicious JavaScript executed by signed node.exe; stages second-tier payloads including ModeloRAT (modular remote access trojan), EtherRAT, AsukaStealer (credential/browser/session theft), and C2Looper.
  • C2 communication: Dual-track — traditional HTTP(S) beaconing to actor domains (mueleer.com, grande-luna.top, oeannon.com) plus EtherHiding: payloads/C2 configs retrieved via blockchain RPC gateways such as mainnet.gateway.tenderly.co, making takedown-resistant infrastructure.
  • Persistence: Registry Run keys and scheduled tasks masquerading as Node.js update jobs; some variants persist via npm global package directories.
  • Anti-analysis: Execution via signed binary defeats allowlisting; blockchain staging defeats DNS-based takedowns; payload delivery is gated after repeated blocking attempts (geo/User-Agent filtering observed in the Asian technology company intrusion).

AdaptixC2 (Post-Exploitation Framework)

  • Increasingly adopted as a Cobalt Strike alternative. In the PaperCut intrusion, it was embedded in a trojanized Microsoft Copilot binary — abusing trust in signed-adjacent AI tooling.
  • Beacons over HTTP(S) with configurable malleable profiles; supports in-memory BOF-style extension jobs, credential dumping, and lateral movement via SMB/WMI.
  • The PaperCut chain: zero-day exploitation → in-memory Java loader → web shell → trojanized binary → AdaptixC2 beacon → credential dumping → domain compromise.

IOC Analysis

The indicator set contains four operational types:

  • Hostnames/Domains: mainnet.gateway.tenderly.co (blockchain RPC gateway abused for EtherHiding staging — note this is legitimate infrastructure being abused, so block with context: alert on any corporate endpoint resolving blockchain RPC gateways), mueleer.com, grande-luna.top, oeannon.com, challenge-refernow.com, csa-humanchecknow.com, mail.authorized-logins.net, www.xt24.com. Operationalize via DNS sinkholing and proxy blocks; hunt retroactively in DNS logs for the past 90 days given the campaign's February 2026 start.
  • IPv4: 156.227.0.13 — AdaptixC2 C2 tied to the PaperCut intrusion. Block at egress and hunt netflow/proxy logs.
  • CVEs: CVE-2026-82078, CVE-2026-81578 (exploited zero-days in PaperCut MF 24.0.2), plus CVE-2026-88771 and CVE-2026-88772. Feed to vuln management; any PaperCut MF instance reachable from the internet is an emergency patch/isolation candidate.
  • SHA256 hashes: d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222, cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c, bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58 — the Java loader, web shell, and trojanized Copilot binary. Push to EDR blocklists and sweep with your AV/EDR custom IOC scan. Tools for decoding/triage: MISP or OpenCTI for IOC management, CyberChef for payload deobfuscation, VirusTotal/MalwareBazaar for hash enrichment.

Detection Engineering

YAML
---
title: Node.exe Executing Suspicious JavaScript Payload
description: Detects the legitimate Node.js runtime executing inline or downloaded JavaScript — the core execution primitive of the Woodgnat ClickFix campaign delivering ModeloRAT, EtherRAT, and AdaptixC2.
logsource:
  category: process_creation
  product: windows
  service: sysmon
detection:
  selection_image:
    Image|endswith: '\node.exe'
  selection_cmd:
    CommandLine|contains:
      - ' -e '
      - '--eval'
      - 'Invoke-Expression'
      - 'https://'
      - 'http://'
      - 'fetch('
      - 'require(''child_process'')'
  filter_userprofile:
    Image|contains:
      - '\AppData\'
      - '\Users\Public\'
      - '\ProgramData\'
  condition: selection_image and selection_cmd and not filter_userprofile
falsepositives:
  - Developer workstations running Node.js with inline eval
  - Legitimate npm tooling
tags:
  - attack.defense_evasion
  - attack.t1218
  - attack.t1059.007
level: high
status: experimental
date: 2026/10/03
author: Security Arsenal Threat Intelligence
---
title: ClickFix Clipboard Execution via PowerShell or mshta
logsource:
  category: process_creation
  product: windows
  service: sysmon
description: Detects ClickFix-style user-driven execution where a fake verification page causes a user to paste commands launching node.js installers, mshta, or curl-based payload retrieval.
detection:
  selection_parent:
    ParentImage|endswith:
      - '\explorer.exe'
      - '\msedge.exe'
      - '\chrome.exe'
      - '\firefox.exe'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\mshta.exe'
      - '\curl.exe'
      - '\msiexec.exe'
  selection_cmd:
    CommandLine|contains:
      - 'nodejs.org'
      - 'node-v'
      - '-enc'
      - 'IEX'
      - 'iwr '
  condition: selection_parent and selection_child and selection_cmd
falsepositives:
  - Administrators installing Node.js from a browser-initiated download
level: high
status: experimental
date: 2026/10/03
author: Security Arsenal Threat Intelligence
tags:
  - attack.initial_access
  - attack.t1204
---
title: PaperCut MF Web Shell or Java Loader Process Spawn
description: Detects PaperCut MF application server spawning shells, Java loaders, or scripting interpreters — consistent with CVE-2026-82078 / CVE-2026-81578 exploitation leading to web shell deployment and AdaptixC2 delivery.
logsource:
  category: process_creation
  product: windows
  service: sysmon
detection:
  selection_parent:
    ParentImage|contains:
      - '\papercut\'
      - 'pc-app.exe'
      - 'pc-server.exe'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\java.exe'
      - '\javaw.exe'
      - '\w3wp.exe'
      - '\rundll32.exe'
      - '\regsvr32.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Rare; PaperCut spawning system shells is highly anomalous
level: critical
status: experimental
date: 2026/10/03
author: Security Arsenal Threat Intelligence
tags:
  - attack.persistence
  - attack.t1505.003
  - attack.execution
KQL — Microsoft Sentinel / Defender
let ioc_domains = dynamic(["mueleer.com","grande-luna.top","oeannon.com","challenge-refernow.com","csa-humanchecknow.com","mail.authorized-logins.net","www.xt24.com","mainnet.gateway.tenderly.co"]);
let ioc_ips = dynamic(["156.227.0.13"]);
let ioc_hashes = dynamic(["d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222","cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c","bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58"]);
union isfuzzy=true
(DeviceNetworkEvents
| where TimeGenerated > ago(90d)
| where RemoteUrl has_any (ioc_domains) or RemoteIP in (ioc_ips)
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteIP, RemoteUrl, RemotePort),
(DeviceProcessEvents
| where TimeGenerated > ago(90d)
| where SHA256 in (ioc_hashes)
   or (FileName =~ "node.exe" and ProcessCommandLine has_any ("--eval"," -e ","fetch(","http"))
   or (InitiatingProcessFolderPath has "papercut" and FileName in~ ("cmd.exe","powershell.exe","java.exe","rundll32.exe"))
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine),
(DeviceFileEvents
| where TimeGenerated > ago(90d)
| where SHA256 in (ioc_hashes)
| project TimeGenerated, DeviceName, FolderPath, FileName, SHA256, InitiatingProcessFileName)
| sort by TimeGenerated desc
PowerShell
# Security Arsenal — Woodgnat Node.js / AdaptixC2 / PaperCut Hunt Script
$IOCs = @{
    Domains = @('mueleer.com','grande-luna.top','oeannon.com','challenge-refernow.com','csa-humanchecknow.com','mail.authorized-logins.net','www.xt24.com','mainnet.gateway.tenderly.co')
    IPs     = @('156.227.0.13')
    Hashes  = @('d2e55213a02fd16a077298c986130522eb63196bdf8a8c1aec0eed6ef318b222','cf6dd15baf5ef66432a95b5a2ec64ba5c6de565b3fb9e10ae01b1a91612a1c2c','bc5fd75b307c2a11a602fbedb8275e0836ddf81cdd43af00a6bf0d850ff6cf58')
}

Write-Host "[1] Checking active network connections to C2 infrastructure..."
Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue |
  Where-Object { $_.RemoteAddress -in $IOCs.IPs } |
  Select-Object LocalAddress,LocalPort,RemoteAddress,RemotePort,OwningProcess |
  Format-Table -AutoSize

Write-Host "[2] Checking DNS cache for malicious domain resolutions..."
Get-DnsClientCache -ErrorAction SilentlyContinue |
  Where-Object { $d = $_.Entry; ($IOCs.Domains | Where-Object { $d -like "*$_*" }) } |
  Select-Object Entry, Data, Status | Format-Table -AutoSize

Write-Host "[3] Hunting rogue node.exe instances outside standard install paths..."
Get-Process -Name node -ErrorAction SilentlyContinue |
  Where-Object { $_.Path -notlike '*Program Files*' } |
  Select-Object Id, Path, StartTime | Format-Table -AutoSize

Write-Host "[4] Checking persistence: Run keys referencing node.js or suspicious JS..."
$runKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run')
foreach ($key in $runKeys) {
  Get-ItemProperty $key -ErrorAction SilentlyContinue | Get-Member -MemberType NoteProperty |
    Where-Object { $_.Name -notmatch 'PS' } | ForEach-Object {
      $val = (Get-ItemProperty $key -Name $_.Name).$($_.Name)
      if ($val -match 'node\.exe|\.js|mshta|powershell.*-enc') {
        Write-Host "  SUSPICIOUS: $key :: $($_.Name) = $val" -ForegroundColor Red
      }
    }
}

Write-Host "[5] Checking scheduled tasks executing node.exe, mshta, or JS payloads..."
Get-ScheduledTask | ForEach-Object {
  $actions = $_.Actions | ForEach-Object { "$($_.Execute) $($_.Arguments)" }
  if ($actions -match 'node\.exe|mshta|\.js |iwr |curl ') {
    Write-Host "  REVIEW: $($_.TaskName) :: $actions" -ForegroundColor Yellow
  }
}

Write-Host "[6] Sweeping common staging paths for known malicious hashes..."
$paths = @("$env:TEMP","$env:PUBLIC","$env:ProgramData","$env:APPDATA")
foreach ($p in $paths) {
  Get-ChildItem $p -Recurse -File -ErrorAction SilentlyContinue | ForEach-Object {
    $h = (Get-FileHash $_.FullName -Algorithm SHA256 -ErrorAction SilentlyContinue).Hash
    if ($h -and ($IOCs.Hashes -contains $h.ToLower())) {
      Write-Host "  MALICIOUS FILE: $($_.FullName) [$h]" -ForegroundColor Red
    }
  }
}

Write-Host "[7] Checking for trojanized Copilot binary / unsigned Copilot instances..."
Get-ChildItem "$env:LOCALAPPDATA\Microsoft","$env:ProgramFiles" -Recurse -Filter '*copilot*.exe' -ErrorAction SilentlyContinue |
  ForEach-Object {
    $sig = Get-AuthenticodeSignature $_.FullName
    if ($sig.Status -ne 'Valid' -or $sig.SignerCertificate.Subject -notmatch 'Microsoft') {
      Write-Host "  INVALID SIGNER: $($_.FullName) — Status: $($sig.Status)" -ForegroundColor Red
    }
  }

Write-Host "Hunt complete. Review any RED output immediately and isolate the host."

Response Priorities

Immediate (0-4 hours):

  • Block all listed domains and 156.227.0.13 at DNS, proxy, and egress firewall. Add SHA256 hashes to EDR blocklists.
  • Hunt for node.exe executing from non-standard paths (AppData, ProgramData, Public) and for any endpoint resolving blockchain RPC gateways (EtherHiding staging).
  • Identify all PaperCut MF instances — especially internet-facing ones. If running v24.0.2 or unpatched against CVE-2026-82078 / CVE-2026-81578, take offline or place behind VPN immediately.
  • Verify Authenticode signatures on all Microsoft Copilot binaries in the environment.

24 hours:

  • AsukaStealer and credential dumping in both chains mean identity compromise is probable. Force password resets and revoke sessions/tokens for any user on hosts showing node.exe, ClickFix, or PaperCut-adjacent artifacts. Audit privileged account usage and Kerberos ticket anomalies post-August 31 for education-sector tenants.
  • Retro-hunt DNS and proxy logs back to February 2026 for the lure and C2 domains.
  • Review any recent "user reported a weird verification page" helpdesk tickets — ClickFix victims often self-report without knowing it.

1 week (architecture hardening):

  • Implement application control (WDAC/AppLocker) restricting script interpreters and unsigned/unsigned-adjacent binaries; block node.exe execution for non-developer populations via policy.
  • Deploy browser-level mitigations against ClickFix: block clipboard-to-run workflows via group policy where feasible, and add fake-CAPTCHA lure domains to web filter categories.
  • Segment print infrastructure from the domain; print servers should never have a path to domain compromise. Enforce tiered administration.
  • Add AdaptixC2 beaconing detection (malleable HTTP profiles, periodic beacon deltas) to network monitoring and deploy the Sigma/KQL content above into production.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.