QNodeService
- First seen
- 2020-04-01 00:00:00
- Malware type
- backdoor, credential-stealer
- Last IoC activity
- 2026-07-10 00:11:41
- Profile updated
- 2026-07-07 14:34:02
Context
According to Trend Micro, this is a Node.js based malware, that can download/upload/execute files, steal credentials from Chrome/Firefox browsers, and perform file management, among other things. It targets Windows and has components for both 32 and 64bit.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Js.Qnodeservice (report)
- Trend Micro — Qnodeservice Node Js Trojan Spread Via Covid 19 Lure (report)
- telsy.com — Mar 93433 White (report)