RoadK1ll is a Node.js-based malicious implant and reverse tunneling tool identified by Blackpoint during an incident response engagement. It is designed for post-compromise access maintenance, lateral movement, and internal network pivoting. The implant establishes an outbound WebSocket connection to attacker-controlled infrastructure using a custom protocol, then brokers TCP traffic on demand through the compromised host, effectively turning the infected machine into a relay point for access to internal systems, services, and network segments that are not externally exposed. Its design avoids the need for an inbound listener on the victim host and is intended to blend into normal network traffic.
RoadK1ll multiplexes multiple logical connections over a single WebSocket session and supports concurrent channels. Reported protocol message types include CONNECT, DATA, CONNECTED, CLOSE, and ERROR. It can receive operator instructions to open outbound TCP connections to specified internal hosts and ports, forward raw traffic bidirectionally, confirm successful connections, terminate channels, and return error information. Reported implementation details include use of the Node.js net module for TCP socket handling, the ws module for WebSocket communications, a custom message format with a 4-byte channel identifier and 1-byte message type, and reconnection logic to restore the tunnel if interrupted.
Blackpoint reported that RoadK1ll lacks traditional persistence mechanisms such as registry keys, scheduled tasks, or services in the analyzed component, and operates only while its process remains alive. In the investigated intrusion, Blackpoint assessed that attackers likely began with compromise of an SSL VPN at a managed service provider, deployed RoadK1ll from a node.zip archive dropped in ProgramData, and used it to tunnel traffic out of the environment, move laterally inside the MSP, and search for higher-value access. The actor then obtained NinjaOne secrets, created a rogue technician account, and abused the RMM platform to access servers, workstations, and domain controllers in multiple customer environments. Follow-on activity included transfer of PSTools.zip via temp[.]sh, use of KAPE against ActiveDirectoryNTDS targets, creation of rogue Domain Admin accounts named Support, and deployment of GOST tunneling services. Blackpoint also linked related infrastructure and tooling exposure involving Nezha.
High-confidence indicators directly reported for RoadK1ll include index.js SHA256 b5a3ace8dc6cc03a5d83b2d85904d6e1ee00d4167eb3d04d4fb4f793c9903b7e, node.zip SHA256 cc9c37382669520418db2f953adcbc23b5890a319f662ee8bc8d7840b0809c50, and C2 or related IP addresses including 45.63.39.209, 149.28.244[.]152, 45.76.233[.]211, 149.28.253[.]247, 216.128.134[.]133, 194.87.125[.]253, 142.248.80[.]106, and 104.238.29[.]81, as well as temp[.]sh.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacker can instruct RoadK1ll to open connections to internal services, management interfaces, or other hosts that are not directly exposed externally. Because these connections originate from the compromised machine, they inherit its network trust and positioning, effectively bypassing perimeter controls.
Its sole function is to convert a single compromised machine into a controllable relay point, an access amplifier, through which an operator can pivot to internal systems, services, and network segments that would otherwise be unreachable from outside the perimeter.
RoadK1ll does not rely on an inbound listener on the compromised host. It establishes an outbound WebSocket connection to attacker-controlled infrastructure, which is then used as a tunnel to relay TCP traffic on demand.
RoadK1ll is a Node.js-based reverse tunneling implant that establishes an outbound WebSocket connection to attacker-controlled infrastructure... By relying on outbound web-style traffic and avoiding the need for inbound listeners, RoadK1ll blends into normal network activity.
The malware is a Node.js implant that communicates over a custom WebSocket protocol to sustain ongoing attacker access and enable further operations. The researchers describe it as a lightweight reverse tunneling implant that blends into normal network activity and turns an infected machine into a relay point for the attacker. | Furthermore, RoadK1ll supports multiple concurrent connections over the same tunnel, allowing its operator to communicate with several destinations at once.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RoadK1ll is a lightweight reverse tunneling Node.js implant that establishes outbound WebSocket connections to attacker-controlled infrastructure, turning an infected host into a relay point for covert access to internal systems and forwarding TCP traffic on demand.
RoadK1ll is a lightweight Node.js reverse tunneling implant that establishes an outbound WebSocket connection to attacker-controlled infrastructure and turns an infected machine into a controllable relay point. It is used for covert pivoting, relaying TCP traffic to internal systems, maintaining access through reconnection, and bypassing perimeter controls by leveraging the compromised host's network trust.
A Node.js-based reverse tunnel used to move traffic out of the environment, enable internal pivoting, support lateral movement, and help the actor identify NinjaOne secrets and expand access from the MSP into customer environments.
A Node.js-based reverse tunneling implant used to maintain reliable access after compromise by creating an outbound WebSocket tunnel to attacker infrastructure and brokering multiple TCP connections for pivoting and lateral movement inside victim networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.