According to reports from network sources, thousands of computers running Windows have been infected by a new type of malware that downloads and installs a copy of the Node.js infrastructure, converting the infected systems into proxy servers used for fraudulent activities.

The malware, referred to as Nodersok in Microsoft's report and Divergent in Cisco Talos's report, was discovered this summer. It spread through malicious advertising that forced HTML Application files to be downloaded onto computers. Users who executed these files on their PCs triggered a multi-stage infection process utilizing Excel, JavaScript, and PowerShell scripts, ultimately leading to the download and installation of the Nodersok malware.
The malware itself comprises several components designed to serve different purposes. For example, a PowerShell module is used to disable Windows Update and standard protection. Additionally, there is a module used to elevate the malware's privileges within the system. However, it also includes legitimate applications: WinDivert and Node.js. The former is used for capturing and interacting with network packets, while the latter allows JavaScript to run on web servers.
Reports from Microsoft and Cisco indicate that the malware uses two legitimate applications to run proxiesserver on infected machines. According to Microsoft, the malware turns infected nodes into proxiesservers for transmitting malicious traffic. Cisco's report states that the proxies are used for committing fraudulent activities.
To prevent infections, experts recommend not executing HTML Application files found on PCs, especially if their origin is unknown. In any case, files that are unexpectedly downloaded from web pages are always a bad sign and should not be trusted, regardless of their extension.
Source: 3dnews.ru
