NOVABLIGHT is a modular Node.js and Electron-based malware-as-a-service information stealer. It is marketed to customers that can generate configurable payloads and access a dashboard for stolen victim data. Activity has been associated with French-speaking operators and is assessed as likely linked to the Sordeal Group, which has also been associated with Nova Sentinel and MALICORD.
NOVABLIGHT has been distributed through fake video-game installer lures. It targets Windows systems and collects browser credentials and data, cryptocurrency-wallet information, saved Wi-Fi passwords, system and hardware details, running processes, security-product information, screenshots, clipboard data, webcam recordings, and files selected using sensitive-data keywords. It can decrypt data from Chromium-based browsers and inject modified code into Electron applications, including messaging, VPN, email, and cryptocurrency-wallet software. Its wallet-focused functionality includes intercepting wallet passphrases in targeted applications and replacing cryptocurrency or payment addresses copied to the clipboard with attacker-controlled addresses.
The malware supports exfiltration through an operator-controlled web panel, messaging-platform channels, webhooks, and third-party file-transfer services. It employs extensive JavaScript obfuscation, anti-debugging and virtual-machine detection, remotely maintained analysis-environment blocklists, and termination of selected security-analysis processes. Configured builds can attempt to impair Microsoft Defender and Task Manager, disrupt network connectivity, disable Windows recovery features, remove volume shadow copies, hinder deletion of the malware, and alter local user group membership.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“NOVABLIGHT is a NodeJS-based Malware-as-a-Service (MaaS) information stealer” and “a modular and feature-rich information stealer built on NodeJS with the Electron framework.”
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware executes PowerShell commands including Get-CimInstance for antivirus discovery, Get-Clipboard, and removal of the victim account from privileged groups.
NOVABLIGHT uses netsh to disable adapters, reagentc /disable to disable Windows Recovery Environment, vssadmin delete shadows /all, tasklist, and netsh wlan profile commands.
NOVABLIGHT is a modular information stealer built on NodeJS with the Electron framework.
The URL prompted the user to download a binary and install a French-language version of a game.
NOVABLIGHT can inject malicious code into several popular Electron-based applications... The injection implementation is a classic example of Electron App repacking: unpacking the ASAR file, rewriting any targeted source files, then repacking it... targeting applications such as: Discord client, Exodus wallet, Mullvad VPN client, Atomic wallet, Mailspring email client
NOVABLIGHT uses a large global lookup array, Base91-encoded strings, flattened proxy objects, dispatcher-based control-flow obfuscation, and proxy variables.
Multiple campaigns leveraged fake video-game installer downloads; one site offered a French-language game with a name and description comparable to a recently released Steam game.
Checks include VM GPU names, blacklisted usernames, VM driver files, low screen resolution, missing USB devices, and remote blacklists of IPs, HWIDs, organizations, programs, and OS names.
NOVABLIGHT can inject malicious code into several popular Electron-based applications... The injection implementation is a classic example of Electron App repacking: unpacking the ASAR file, rewriting any targeted source files, then repacking it... targeting applications such as: Discord client, Exodus wallet, Mullvad VPN client, Atomic wallet, Mailspring email client
captureTaskList executes tasklist /FO CSV /NH and saves the results to TaskManagerInfo.txt.
captureSystemInfo gathers HWID, CPU and GPU models, RAM, disk information, Windows version, and connected USB devices.
Collected system information, screenshots, task lists, antivirus details, clipboard data, webcam video, Wi-Fi passwords, and matching files are saved locally before upload; matching files are archived as files.zip.
captureScreen captures a full screenshot of the victim desktop using the screenshot-desktop library.
captureClipboardContent executes Get-Clipboard; the clipper module monitors the clipboard for cryptocurrency or PayPal addresses and replaces them.
There are 3 channels for the stolen data: the official web panel owned by the NOVABLIGHT group, the Discord webhook API, and the Telegram API... the module falls back to communicating directly with the official Telegram API... Unlike the Telegram module, the Discord webhook implementation is much simpler. It utilizes a single URL for exfiltration
When the antireset flag is enabled, the malware runs reagentc /disable and vssadmin delete shadows /all.
To disrupt the victim's internet connection, the malware employs two distinct methods. The first involves persistently disabling the Wi-Fi adapter... The second method disables the primary “Ethernet” network adapter using the netsh command, running it every 5 seconds to disable re-enabling attempts.
44 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modular Node.js/Electron-based information stealer targeting credentials and cryptocurrency wallets, with sandbox detection and obfuscation.
NOVABLIGHT is a Node.js-based infostealer offered as malware-as-a-service (MaaS), operated by French-speaking threat actors.
A modular NodeJS/Electron-based information stealer sold as MaaS. It steals credentials and browser data, captures screenshots, clipboard contents, webcam video, Wi-Fi passwords, and files, performs Electron app injections, substitutes crypto/PayPal clipboard addresses, exfiltrates data via web panel/Discord/Telegram, and includes anti-analysis, persistence, and system sabotage features such as disabling Defender, disrupting networking, and impairing recovery.
NodeJS/Electron-based MaaS infostealer sold and built through Telegram and Discord. It harvests credentials, browser data, system information, screenshots, clipboard contents, webcam video, saved Wi-Fi passwords, and keyword-matched files; can inject/trojanize Electron applications, replace crypto and PayPal clipboard addresses, impair security and recovery functions, evade sandboxes, and exfiltrate data through its panel, Discord, Telegram, and file-hosting services.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.