⤷ Title: Malware Disguised as SteamCleaner Uses Valid Signature to Inject Node.js RCE Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:22:09 +0000
════════════════════════
⌗ Tags: #Malware #anti_sandbox #InnoSetup #Node.js RCE #proxyware #Remote Code Execution #Signed Malware #SteamCleaner
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:22:09 +0000
════════════════════════
⌗ Tags: #Malware #anti_sandbox #InnoSetup #Node.js RCE #proxyware #Remote Code Execution #Signed Malware #SteamCleaner
Daily CyberSecurity
Malware Disguised as SteamCleaner Uses Valid Signature to Inject Node.js RCE Backdoor
ASEC exposed a SteamCleaner malware clone signed with a valid certificate. It installs a Node.js RCE backdoor via InnoSetup, evades sandboxes, and is suspected of running Proxyware for profit.