Malware, Network Security

RoadK1ll malware enables stealthy network pivoting

A new malicious implant named RoadK1ll is allowing threat actors to quietly move from a compromised host to other systems within a network. This Node.js implant utilizes a custom WebSocket protocol for communication, enabling sustained attacker access and further operations. The malware was discovered by Blackpoint during an incident response engagement, as reported by Bleeping Computer.

RoadK1ll functions as a lightweight reverse tunneling implant, designed to blend into normal network traffic and transform an infected machine into a relay point for attackers. It establishes an outbound WebSocket connection to attacker-controlled infrastructure, bypassing the need for an inbound listener on the compromised host. This allows attackers to forward TCP traffic on demand through a single tunnel, remaining undetected for extended periods and accessing internal systems, services, and network segments that are not directly exposed externally.

The malware supports multiple concurrent connections and a basic set of commands including CONNECT, DATA, CONNECTED, CLOSE, and ERROR. While it lacks traditional persistence mechanisms, its process-based operation and efficient covert communication make it flexible and easy to deploy.

Source: Bleeping Computer

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds