GachiLoader is a heavily obfuscated Node.js/JavaScript malware loader distributed as a large (≈60–90 MB) self-contained Windows executable created with the nexe packer (bundled Node.js runtime). It has been observed in the “YouTube Ghost Network,” where compromised YouTube accounts post lure videos (e.g., game cheats/cracked software) that link to password-protected archives hosted on external file-hosting services; video descriptions often include the archive password and instructions to disable Microsoft Defender. Check Point observed the campaign since at least 2024-12-22, spanning 39 compromised accounts and 100+ videos (~220,000 views), with the final payload in the analyzed chain being the Rhadamanthys infostealer.
Behavior and capabilities reported include extensive anti-VM/anti-analysis checks (e.g., minimum RAM/CPU core checks; username/hostname/process blocklists; PowerShell/WMI queries such as Win32_PortConnector, Win32_DiskDrive, Win32_VideoController). If a lab environment is detected, it may enter an endless loop of HTTP GET requests to benign sites (e.g., linkedin.com, grok.com, whatsapp.com, twitter.com). It uses a per-sample mutex-like .lock file in %TEMP% and exits if it already exists or was recently modified. It checks for elevation via net session and may relaunch itself with Start-Process -Verb RunAs (UAC prompt).
For defense evasion, GachiLoader attempts to kill Windows Defender’s SecHealthUI.exe (taskkill /F /IM SecHealthUI.exe) and adds Microsoft Defender exclusions via Add-MpPreference (e.g., C:\Users, C:\ProgramData, C:\Windows, drive roots, and the .sys extension).
Payload delivery has two described variants: (1) a remote-payload flow where it collects host information (including AV products and OS version) and POSTs it to a /log endpoint, then requests /richfamily/<key> with an X-Secret: gachifamily header to obtain a Base64-encoded URL; the server requires a correct embedded key in the X-Secret header or returns Forbidden. The downloaded payload is saved to %TEMP% under a random legitimate-looking name (e.g., KeePass.exe, GoogleDrive.exe, UnrealEngine.exe) and was described as packed/protected with VMProtect or Themida. (2) a staged flow where it drops a second-stage loader kidkadi.node (a Node.js native addon loaded via dlopen) with an embedded payload.
Some GachiLoader infections deploy the second-stage Kidkadi loader, which implements a previously undocumented PE injection approach dubbed “Vectored Overloading.” This technique abuses Vectored Exception Handling (VEH) and hardware breakpoints to emulate syscalls (e.g., NtOpenSection/NtMapViewOfSection) and to trick the Windows loader into mapping a malicious PE from memory while appearing backed by a legitimate DLL (e.g., wmp.dll): it creates an SEC_IMAGE section from a legitimate DLL, overwrites it with the payload, maps it, and swaps in the malicious section during LoadLibrary.
Open-source tooling referenced in the reporting includes nexe_unpacker (to extract obfuscated JS from the packed PE) and Check Point’s Nodejs-Tracer and Vectored Overloading reimplementation repositories.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader malware mentioned as being distributed via cracked software and YouTube videos (no additional technical details provided in the content excerpt).
Node.js-based malware loader featuring heavy obfuscation and a PE injection technique; deploys a second-stage loader (Kidkadi).
GachiLoader is a new loader malware that hides in YouTube video links, likely used to deliver additional malicious payloads to victims.
Node.js-based malware loader distributed via malicious YouTube videos, used to load additional malware onto victim systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.