typeentityconfidencemediumcreated2026-08-21updated2026-08-21malware-familyratinfostealerc2scriptdefense-evasiondiscoverypersistenceexfiltrationc2-protocolmitre-attck

Nova Shadow

A French-language Node.js JavaScript RAT/stealer family distributed as obfuscated single-file scripts bundled with Parcel. Branded "Nova Shadow" by its author, it uses Socket.IO for real-time C2, steals browser credentials via DPAPI/AES-GCM and Chrome DevTools Protocol, injects Discord's desktop_core, exfiltrates to GoFile.io, and notifies operators via Discord webhook and Telegram Bot API.

Build Stack

  • Language: JavaScript (Node.js runtime required)
  • Bundler: Parcel (parcelRequire module loader)
  • Obfuscator: javascript-obfuscator (control-flow flattening, string-array lookup, dead-code injection, __p_ prefix mangling)
  • Package manager: npm (inferred from module structure)

Capabilities

  • socketio-c2-transport
  • browser-credential-harvesting
  • discord-desktop-core-injection
  • discord-webhook-c2-exfiltration
  • telegram-bot-exfiltration
  • gofile-exfiltration
  • cdp-browser-injection
  • uac-bypass-vbscript-shellapplication
  • registry-Run-persistence
  • remote-blacklist-process-killing
  • screenshare-remote-desktop
  • file-transfer-socketio
  • powershell-remote-shell

Variants / Siblings

  • First confirmed sibling: 7ab76063080e0903e58733c6e136f6816a6e26b33be0207b9a34d94c44c2b520 (atribuyeres_deobfuscated.js, 592 KB, May 2026)

Notable Analyses

  • /intel/analyses/7ab76063080e0903e58733c6e136f6816a6e26b33be0207b9a34d94c44c2b520.html — First confirmed sample; full static reverse engineering

Related Entities / Techniques