{"id":11738,"date":"2026-03-31T10:04:58","date_gmt":"2026-03-31T10:04:58","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/31\/hackers-deploy-roadk1ll-pivoting-malware-to-turn-compromised-hosts-into-network-relays\/"},"modified":"2026-03-31T10:04:58","modified_gmt":"2026-03-31T10:04:58","slug":"hackers-deploy-roadk1ll-pivoting-malware-to-turn-compromised-hosts-into-network-relays","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/31\/hackers-deploy-roadk1ll-pivoting-malware-to-turn-compromised-hosts-into-network-relays\/","title":{"rendered":"Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays"},"content":{"rendered":"<p>    Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new piece of malware called RoadK1ll has been found silently converting compromised machines into controllable network relay points. <\/p>\n<p>Unlike most malware that arrives loaded with commands and attack tools, RoadK1ll is deliberately lean, built around one goal: giving attackers a reliable and silent path deeper into a network after initial compromise. <\/p>\n<p>That narrow focus makes it genuinely dangerous, not for what it does alone, but for what it enables afterward.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/27023515-47e0-4556-afa8-4d1a5993ea71\/Hackers-Deploy-RoadK1ll-Pivoting-Malware-to-Turn-Compromised-Hosts-Into-Network-Relays.pdf?AWSAccessKeyId=ASIA2F3EMEYEUNUJDHQ2&amp;Signature=gXWTaZvAZ3wWXTpHs9FVlpCIlxU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEG8aCXVzLWVhc3QtMSJHMEUCIQCViPYOrFybj8kwoh1d0IIJz0imxHejYFYIQl7bKdTY1AIgf2Lm9ltrus0fTttCZXuiYxy8E4AKidP8uglvSb7A1Cwq8wQIOBABGgw2OTk3NTMzMDk3MDUiDLSpIo6A2YmpovT7kirQBOwtbeJEMhj8kQ5X%2BcAzReY26fgt1r7QbBv%2FiKIf%2FelbYZIePxuH1%2FmQyJTM39R1zdWhOyXJ%2FYY9vym0RH%2B6N2XDyxAOl2a6FStAeHcxd8%2BEHmDB3U6AfX2p1wOP5m4ORj2fLd9gFd%2F08e%2F3VZepCr6cRe5ynGF40OnoZjvNjQLzEz2mAL0LFvio2ps42GEOHJ%2FmWRHXKicx9SoOAosEABeRbJPjzKqeatllJgiHlMCoCXIAEWe5DVT%2Fdq3sQcNxHYIfX7lU1LQAF0AXrhI7j58BJQa8952ca9uTN2qZNEwGGuHstUqmFPlv9%2B0hdOAIBvBeBsOPN9CHL8lg1k34I9WMV2QKe7mOY%2BjF%2FAgRvGCtiBVrIndSP5j6HKYRx%2Fkkm9BnSAnBMNu0gT%2B%2FjiMSBmMVxoysGwPqG%2Ft0CYe4j6Qv%2F1unRD%2F%2Be6taVvVcTEfAbS1MgN8qMVVh7mEVWGpK0mJwS%2BY%2BGssfDG3rafoSfnFdStbMFJMgK35ezozVwsnn5cQK9RhPwb4uELaid9jkY7OphLmOzwJLwhhk3entqiZkA9RQ%2B0azOlJODSlC1y5pVcwAmaufpkXAYrlTYThSczMdmG%2BtJLN9pwiqR7eBdNLOl1owWRK37yj0ok%2BYvnta9A5u3sFPD6FxIfNrtEmHW90PqfREVHlQiX8YjzEunreep%2BGyI6IQfeqOiEl0CTSefCXpwh6SVMTfrlVCYEuR%2B1C5AIuNvz3dX0mrF2XGsYrXs8K4FIEA8ypbZsYGjrtFvdXYDwInEWA7%2BHyDJjDJI00w3N6tzgY6mAHMSmoLsoL4KOle99Kh2N5PJiNOx9LJ59nUMBxoXM%2B9PsWsWRQ5m%2BttHEYkjp%2BAT6TCmMyYoiIK50FHMFKBlqh1aAA0ZvjCatk3QNIa%2BqUlUh7jjM2WxBZs%2FX2r%2FGVmhRPz8DUIJ7yzCCirqkexK%2ByOiOulSGuhnsQ19fI9fSms20nb8IRmxWKUdCbscQ6%2Fn8%2BRAMfZkEgMaw%3D%3D&amp;Expires=1774942347\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>RoadK1ll is a Node.js-based reverse tunneling implant that establishes an outbound WebSocket connection from the infected machine to attacker-controlled infrastructure. <\/p>\n<p>Once that connection is live, the compromised host becomes a relay, and the attacker can push instructions through this channel, directing the system to open TCP connections to internal hosts or segments normally cut off from outside access. <\/p>\n<p>A single infected machine can unlock entire sections of a network that security teams believed were safely isolated.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/27023515-47e0-4556-afa8-4d1a5993ea71\/Hackers-Deploy-RoadK1ll-Pivoting-Malware-to-Turn-Compromised-Hosts-Into-Network-Relays.pdf?AWSAccessKeyId=ASIA2F3EMEYEUNUJDHQ2&amp;Signature=gXWTaZvAZ3wWXTpHs9FVlpCIlxU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEG8aCXVzLWVhc3QtMSJHMEUCIQCViPYOrFybj8kwoh1d0IIJz0imxHejYFYIQl7bKdTY1AIgf2Lm9ltrus0fTttCZXuiYxy8E4AKidP8uglvSb7A1Cwq8wQIOBABGgw2OTk3NTMzMDk3MDUiDLSpIo6A2YmpovT7kirQBOwtbeJEMhj8kQ5X%2BcAzReY26fgt1r7QbBv%2FiKIf%2FelbYZIePxuH1%2FmQyJTM39R1zdWhOyXJ%2FYY9vym0RH%2B6N2XDyxAOl2a6FStAeHcxd8%2BEHmDB3U6AfX2p1wOP5m4ORj2fLd9gFd%2F08e%2F3VZepCr6cRe5ynGF40OnoZjvNjQLzEz2mAL0LFvio2ps42GEOHJ%2FmWRHXKicx9SoOAosEABeRbJPjzKqeatllJgiHlMCoCXIAEWe5DVT%2Fdq3sQcNxHYIfX7lU1LQAF0AXrhI7j58BJQa8952ca9uTN2qZNEwGGuHstUqmFPlv9%2B0hdOAIBvBeBsOPN9CHL8lg1k34I9WMV2QKe7mOY%2BjF%2FAgRvGCtiBVrIndSP5j6HKYRx%2Fkkm9BnSAnBMNu0gT%2B%2FjiMSBmMVxoysGwPqG%2Ft0CYe4j6Qv%2F1unRD%2F%2Be6taVvVcTEfAbS1MgN8qMVVh7mEVWGpK0mJwS%2BY%2BGssfDG3rafoSfnFdStbMFJMgK35ezozVwsnn5cQK9RhPwb4uELaid9jkY7OphLmOzwJLwhhk3entqiZkA9RQ%2B0azOlJODSlC1y5pVcwAmaufpkXAYrlTYThSczMdmG%2BtJLN9pwiqR7eBdNLOl1owWRK37yj0ok%2BYvnta9A5u3sFPD6FxIfNrtEmHW90PqfREVHlQiX8YjzEunreep%2BGyI6IQfeqOiEl0CTSefCXpwh6SVMTfrlVCYEuR%2B1C5AIuNvz3dX0mrF2XGsYrXs8K4FIEA8ypbZsYGjrtFvdXYDwInEWA7%2BHyDJjDJI00w3N6tzgY6mAHMSmoLsoL4KOle99Kh2N5PJiNOx9LJ59nUMBxoXM%2B9PsWsWRQ5m%2BttHEYkjp%2BAT6TCmMyYoiIK50FHMFKBlqh1aAA0ZvjCatk3QNIa%2BqUlUh7jjM2WxBZs%2FX2r%2FGVmhRPz8DUIJ7yzCCirqkexK%2ByOiOulSGuhnsQ19fI9fSms20nb8IRmxWKUdCbscQ6%2Fn8%2BRAMfZkEgMaw%3D%3D&amp;Expires=1774942347\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p><a href=\"https:\/\/blackpointcyber.com\/blog\/roadk1ll-a-websocket-based-pivoting-implant\/\" id=\"https:\/\/blackpointcyber.com\/blog\/roadk1ll-a-websocket-based-pivoting-implant\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Blackpoint Response Operations Center (BROC) analysts identified RoadK1ll<\/a> during analysis of a recent network intrusion. <\/p>\n<p>Researchers Nevan Beal and Sam Decker published their findings on March 19, 2026, describing the implant as a purpose-built post-compromise capability rather than a traditional <a href=\"https:\/\/cybersecuritynews.com\/hackers-visual-studio-code-remote-access\/\" id=\"80123\" target=\"_blank\" rel=\"noreferrer noopener\">remote access tool<\/a>. <\/p>\n<p>What stood out most was how it was designed not to carry out direct attacks, but to expand the reach of an initial breach by turning one compromised host into a reusable pivot point for broader movement.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/27023515-47e0-4556-afa8-4d1a5993ea71\/Hackers-Deploy-RoadK1ll-Pivoting-Malware-to-Turn-Compromised-Hosts-Into-Network-Relays.pdf?AWSAccessKeyId=ASIA2F3EMEYEUNUJDHQ2&amp;Signature=gXWTaZvAZ3wWXTpHs9FVlpCIlxU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEG8aCXVzLWVhc3QtMSJHMEUCIQCViPYOrFybj8kwoh1d0IIJz0imxHejYFYIQl7bKdTY1AIgf2Lm9ltrus0fTttCZXuiYxy8E4AKidP8uglvSb7A1Cwq8wQIOBABGgw2OTk3NTMzMDk3MDUiDLSpIo6A2YmpovT7kirQBOwtbeJEMhj8kQ5X%2BcAzReY26fgt1r7QbBv%2FiKIf%2FelbYZIePxuH1%2FmQyJTM39R1zdWhOyXJ%2FYY9vym0RH%2B6N2XDyxAOl2a6FStAeHcxd8%2BEHmDB3U6AfX2p1wOP5m4ORj2fLd9gFd%2F08e%2F3VZepCr6cRe5ynGF40OnoZjvNjQLzEz2mAL0LFvio2ps42GEOHJ%2FmWRHXKicx9SoOAosEABeRbJPjzKqeatllJgiHlMCoCXIAEWe5DVT%2Fdq3sQcNxHYIfX7lU1LQAF0AXrhI7j58BJQa8952ca9uTN2qZNEwGGuHstUqmFPlv9%2B0hdOAIBvBeBsOPN9CHL8lg1k34I9WMV2QKe7mOY%2BjF%2FAgRvGCtiBVrIndSP5j6HKYRx%2Fkkm9BnSAnBMNu0gT%2B%2FjiMSBmMVxoysGwPqG%2Ft0CYe4j6Qv%2F1unRD%2F%2Be6taVvVcTEfAbS1MgN8qMVVh7mEVWGpK0mJwS%2BY%2BGssfDG3rafoSfnFdStbMFJMgK35ezozVwsnn5cQK9RhPwb4uELaid9jkY7OphLmOzwJLwhhk3entqiZkA9RQ%2B0azOlJODSlC1y5pVcwAmaufpkXAYrlTYThSczMdmG%2BtJLN9pwiqR7eBdNLOl1owWRK37yj0ok%2BYvnta9A5u3sFPD6FxIfNrtEmHW90PqfREVHlQiX8YjzEunreep%2BGyI6IQfeqOiEl0CTSefCXpwh6SVMTfrlVCYEuR%2B1C5AIuNvz3dX0mrF2XGsYrXs8K4FIEA8ypbZsYGjrtFvdXYDwInEWA7%2BHyDJjDJI00w3N6tzgY6mAHMSmoLsoL4KOle99Kh2N5PJiNOx9LJ59nUMBxoXM%2B9PsWsWRQ5m%2BttHEYkjp%2BAT6TCmMyYoiIK50FHMFKBlqh1aAA0ZvjCatk3QNIa%2BqUlUh7jjM2WxBZs%2FX2r%2FGVmhRPz8DUIJ7yzCCirqkexK%2ByOiOulSGuhnsQ19fI9fSms20nb8IRmxWKUdCbscQ6%2Fn8%2BRAMfZkEgMaw%3D%3D&amp;Expires=1774942347\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The impact of RoadK1ll becomes clear when you consider how quietly it operates inside a network. By using only outbound web-style traffic and never placing an inbound listener on the victim machine, the implant blends naturally into normal network activity. <\/p>\n<p>There is no aggressive scanning, no suspicious open ports, and no large command set that would raise alerts during routine monitoring. The malware simply waits on the infected host, acting only when the attacker sends an instruction through the tunnel.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/27023515-47e0-4556-afa8-4d1a5993ea71\/Hackers-Deploy-RoadK1ll-Pivoting-Malware-to-Turn-Compromised-Hosts-Into-Network-Relays.pdf?AWSAccessKeyId=ASIA2F3EMEYEUNUJDHQ2&amp;Signature=gXWTaZvAZ3wWXTpHs9FVlpCIlxU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEG8aCXVzLWVhc3QtMSJHMEUCIQCViPYOrFybj8kwoh1d0IIJz0imxHejYFYIQl7bKdTY1AIgf2Lm9ltrus0fTttCZXuiYxy8E4AKidP8uglvSb7A1Cwq8wQIOBABGgw2OTk3NTMzMDk3MDUiDLSpIo6A2YmpovT7kirQBOwtbeJEMhj8kQ5X%2BcAzReY26fgt1r7QbBv%2FiKIf%2FelbYZIePxuH1%2FmQyJTM39R1zdWhOyXJ%2FYY9vym0RH%2B6N2XDyxAOl2a6FStAeHcxd8%2BEHmDB3U6AfX2p1wOP5m4ORj2fLd9gFd%2F08e%2F3VZepCr6cRe5ynGF40OnoZjvNjQLzEz2mAL0LFvio2ps42GEOHJ%2FmWRHXKicx9SoOAosEABeRbJPjzKqeatllJgiHlMCoCXIAEWe5DVT%2Fdq3sQcNxHYIfX7lU1LQAF0AXrhI7j58BJQa8952ca9uTN2qZNEwGGuHstUqmFPlv9%2B0hdOAIBvBeBsOPN9CHL8lg1k34I9WMV2QKe7mOY%2BjF%2FAgRvGCtiBVrIndSP5j6HKYRx%2Fkkm9BnSAnBMNu0gT%2B%2FjiMSBmMVxoysGwPqG%2Ft0CYe4j6Qv%2F1unRD%2F%2Be6taVvVcTEfAbS1MgN8qMVVh7mEVWGpK0mJwS%2BY%2BGssfDG3rafoSfnFdStbMFJMgK35ezozVwsnn5cQK9RhPwb4uELaid9jkY7OphLmOzwJLwhhk3entqiZkA9RQ%2B0azOlJODSlC1y5pVcwAmaufpkXAYrlTYThSczMdmG%2BtJLN9pwiqR7eBdNLOl1owWRK37yj0ok%2BYvnta9A5u3sFPD6FxIfNrtEmHW90PqfREVHlQiX8YjzEunreep%2BGyI6IQfeqOiEl0CTSefCXpwh6SVMTfrlVCYEuR%2B1C5AIuNvz3dX0mrF2XGsYrXs8K4FIEA8ypbZsYGjrtFvdXYDwInEWA7%2BHyDJjDJI00w3N6tzgY6mAHMSmoLsoL4KOle99Kh2N5PJiNOx9LJ59nUMBxoXM%2B9PsWsWRQ5m%2BttHEYkjp%2BAT6TCmMyYoiIK50FHMFKBlqh1aAA0ZvjCatk3QNIa%2BqUlUh7jjM2WxBZs%2FX2r%2FGVmhRPz8DUIJ7yzCCirqkexK%2ByOiOulSGuhnsQ19fI9fSms20nb8IRmxWKUdCbscQ6%2Fn8%2BRAMfZkEgMaw%3D%3D&amp;Expires=1774942347\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>This type of low-noise, access-preserving tool is especially concerning for organizations that rely on perimeter-based defenses. <\/p>\n<p>Once RoadK1ll is active, attackers can reach internal databases, administrative interfaces, and segmented environments without ever crossing the outer perimeter again. <\/p>\n<p>The infected machine stops being just a compromised endpoint; it becomes an attacker-controlled gateway into the broader network.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/27023515-47e0-4556-afa8-4d1a5993ea71\/Hackers-Deploy-RoadK1ll-Pivoting-Malware-to-Turn-Compromised-Hosts-Into-Network-Relays.pdf?AWSAccessKeyId=ASIA2F3EMEYEUNUJDHQ2&amp;Signature=gXWTaZvAZ3wWXTpHs9FVlpCIlxU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEG8aCXVzLWVhc3QtMSJHMEUCIQCViPYOrFybj8kwoh1d0IIJz0imxHejYFYIQl7bKdTY1AIgf2Lm9ltrus0fTttCZXuiYxy8E4AKidP8uglvSb7A1Cwq8wQIOBABGgw2OTk3NTMzMDk3MDUiDLSpIo6A2YmpovT7kirQBOwtbeJEMhj8kQ5X%2BcAzReY26fgt1r7QbBv%2FiKIf%2FelbYZIePxuH1%2FmQyJTM39R1zdWhOyXJ%2FYY9vym0RH%2B6N2XDyxAOl2a6FStAeHcxd8%2BEHmDB3U6AfX2p1wOP5m4ORj2fLd9gFd%2F08e%2F3VZepCr6cRe5ynGF40OnoZjvNjQLzEz2mAL0LFvio2ps42GEOHJ%2FmWRHXKicx9SoOAosEABeRbJPjzKqeatllJgiHlMCoCXIAEWe5DVT%2Fdq3sQcNxHYIfX7lU1LQAF0AXrhI7j58BJQa8952ca9uTN2qZNEwGGuHstUqmFPlv9%2B0hdOAIBvBeBsOPN9CHL8lg1k34I9WMV2QKe7mOY%2BjF%2FAgRvGCtiBVrIndSP5j6HKYRx%2Fkkm9BnSAnBMNu0gT%2B%2FjiMSBmMVxoysGwPqG%2Ft0CYe4j6Qv%2F1unRD%2F%2Be6taVvVcTEfAbS1MgN8qMVVh7mEVWGpK0mJwS%2BY%2BGssfDG3rafoSfnFdStbMFJMgK35ezozVwsnn5cQK9RhPwb4uELaid9jkY7OphLmOzwJLwhhk3entqiZkA9RQ%2B0azOlJODSlC1y5pVcwAmaufpkXAYrlTYThSczMdmG%2BtJLN9pwiqR7eBdNLOl1owWRK37yj0ok%2BYvnta9A5u3sFPD6FxIfNrtEmHW90PqfREVHlQiX8YjzEunreep%2BGyI6IQfeqOiEl0CTSefCXpwh6SVMTfrlVCYEuR%2B1C5AIuNvz3dX0mrF2XGsYrXs8K4FIEA8ypbZsYGjrtFvdXYDwInEWA7%2BHyDJjDJI00w3N6tzgY6mAHMSmoLsoL4KOle99Kh2N5PJiNOx9LJ59nUMBxoXM%2B9PsWsWRQ5m%2BttHEYkjp%2BAT6TCmMyYoiIK50FHMFKBlqh1aAA0ZvjCatk3QNIa%2BqUlUh7jjM2WxBZs%2FX2r%2FGVmhRPz8DUIJ7yzCCirqkexK%2ByOiOulSGuhnsQ19fI9fSms20nb8IRmxWKUdCbscQ6%2Fn8%2BRAMfZkEgMaw%3D%3D&amp;Expires=1774942347\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"how-roadk1ll-uses-a-custom-websocket-protocol-to-m\"><strong>How RoadK1ll Uses a Custom WebSocket Protocol to Move Traffic<\/strong><\/h2>\n<p>Rather than using standard <a href=\"https:\/\/cybersecuritynews.com\/fog-ransomware-directory-with-active-directory-exploitation-tools\/\" id=\"102614\" target=\"_blank\" rel=\"noreferrer noopener\">tunneling tools<\/a> or frameworks, RoadK1ll builds its own lightweight communication protocol on top of a single WebSocket connection. <\/p>\n<p>Each message uses a fixed 5-byte header, with the first four bytes identifying the active channel and the fifth defining the message type, followed by the actual data payload. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgMC8mKhkzEBnomNpNPa3gqKAS6V2A7QmCbe0WKg_iWcPlU0joE7BN-lzZX1VUBmObpc-HRdPIcybNVRXOUFv8oyr8BN6GMt-atHGgRFFwVrNbY2Dgpk601vs8sbNmh60-MhSQ485bbyc6-ggsgi_2uuVVlVj00IChbmCf01ekXmVs-RJofyA1Q4JtoOJE\/s16000\/Defining%2520Custom%2520Framing%2520Protocol%2520%28Source%2520-%2520BlackPoint%29.webp?ssl=1\" alt=\"Defining Custom Framing Protocol (Source - BlackPoint)\"><figcaption class=\"wp-element-caption\">Defining Custom Framing Protocol (Source \u2013 BlackPoint)<\/figcaption><\/figure>\n<\/div>\n<p>This structure allows the attacker to run multiple independent sessions over the same tunnel at once, without opening additional connections.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/27023515-47e0-4556-afa8-4d1a5993ea71\/Hackers-Deploy-RoadK1ll-Pivoting-Malware-to-Turn-Compromised-Hosts-Into-Network-Relays.pdf?AWSAccessKeyId=ASIA2F3EMEYEUNUJDHQ2&amp;Signature=gXWTaZvAZ3wWXTpHs9FVlpCIlxU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEG8aCXVzLWVhc3QtMSJHMEUCIQCViPYOrFybj8kwoh1d0IIJz0imxHejYFYIQl7bKdTY1AIgf2Lm9ltrus0fTttCZXuiYxy8E4AKidP8uglvSb7A1Cwq8wQIOBABGgw2OTk3NTMzMDk3MDUiDLSpIo6A2YmpovT7kirQBOwtbeJEMhj8kQ5X%2BcAzReY26fgt1r7QbBv%2FiKIf%2FelbYZIePxuH1%2FmQyJTM39R1zdWhOyXJ%2FYY9vym0RH%2B6N2XDyxAOl2a6FStAeHcxd8%2BEHmDB3U6AfX2p1wOP5m4ORj2fLd9gFd%2F08e%2F3VZepCr6cRe5ynGF40OnoZjvNjQLzEz2mAL0LFvio2ps42GEOHJ%2FmWRHXKicx9SoOAosEABeRbJPjzKqeatllJgiHlMCoCXIAEWe5DVT%2Fdq3sQcNxHYIfX7lU1LQAF0AXrhI7j58BJQa8952ca9uTN2qZNEwGGuHstUqmFPlv9%2B0hdOAIBvBeBsOPN9CHL8lg1k34I9WMV2QKe7mOY%2BjF%2FAgRvGCtiBVrIndSP5j6HKYRx%2Fkkm9BnSAnBMNu0gT%2B%2FjiMSBmMVxoysGwPqG%2Ft0CYe4j6Qv%2F1unRD%2F%2Be6taVvVcTEfAbS1MgN8qMVVh7mEVWGpK0mJwS%2BY%2BGssfDG3rafoSfnFdStbMFJMgK35ezozVwsnn5cQK9RhPwb4uELaid9jkY7OphLmOzwJLwhhk3entqiZkA9RQ%2B0azOlJODSlC1y5pVcwAmaufpkXAYrlTYThSczMdmG%2BtJLN9pwiqR7eBdNLOl1owWRK37yj0ok%2BYvnta9A5u3sFPD6FxIfNrtEmHW90PqfREVHlQiX8YjzEunreep%2BGyI6IQfeqOiEl0CTSefCXpwh6SVMTfrlVCYEuR%2B1C5AIuNvz3dX0mrF2XGsYrXs8K4FIEA8ypbZsYGjrtFvdXYDwInEWA7%2BHyDJjDJI00w3N6tzgY6mAHMSmoLsoL4KOle99Kh2N5PJiNOx9LJ59nUMBxoXM%2B9PsWsWRQ5m%2BttHEYkjp%2BAT6TCmMyYoiIK50FHMFKBlqh1aAA0ZvjCatk3QNIa%2BqUlUh7jjM2WxBZs%2FX2r%2FGVmhRPz8DUIJ7yzCCirqkexK%2ByOiOulSGuhnsQ19fI9fSms20nb8IRmxWKUdCbscQ6%2Fn8%2BRAMfZkEgMaw%3D%3D&amp;Expires=1774942347\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The implant imports two core Node.js modules:\u00a0<code>net<\/code>\u00a0for raw TCP socket handling and\u00a0<code>ws<\/code>\u00a0for managing the WebSocket session.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh9iFK2hyXG561azYouw3XbrGwFzBCG-09sc5dtvgVe86Zcts6s_7TJsjr83BJQAAnqjGTiHAkPkBHVg8Xtlx2nXe7Zm5yN5zqsnz86faGdQCDrzgNmQbNYNOZO-QIUzxbVdhi-UL0Q6SgdBHJ9PQStRWX_m86idQze1OND3N5kBa-paL4q_1vw8iCayPw\/s16000\/Importing%2520the%2520net%2520and%2520ws%2520Modules%2520%28Source%2520-%2520BlackPoint%29.webp?ssl=1\" alt=\"Importing the net and ws Modules (Source - BlackPoint)\"><figcaption class=\"wp-element-caption\">Importing the net and ws Modules (Source \u2013 BlackPoint)<\/figcaption><\/figure>\n<\/div>\n<p>Configuration values in the code define the remote server address, port number, and a shared token that acts as a basic authentication check. <\/p>\n<p>A built-in reconnection timer automatically re-establishes the WebSocket tunnel if the connection drops, keeping the relay active without requiring any manual input from the attacker.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/27023515-47e0-4556-afa8-4d1a5993ea71\/Hackers-Deploy-RoadK1ll-Pivoting-Malware-to-Turn-Compromised-Hosts-Into-Network-Relays.pdf?AWSAccessKeyId=ASIA2F3EMEYEUNUJDHQ2&amp;Signature=gXWTaZvAZ3wWXTpHs9FVlpCIlxU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEG8aCXVzLWVhc3QtMSJHMEUCIQCViPYOrFybj8kwoh1d0IIJz0imxHejYFYIQl7bKdTY1AIgf2Lm9ltrus0fTttCZXuiYxy8E4AKidP8uglvSb7A1Cwq8wQIOBABGgw2OTk3NTMzMDk3MDUiDLSpIo6A2YmpovT7kirQBOwtbeJEMhj8kQ5X%2BcAzReY26fgt1r7QbBv%2FiKIf%2FelbYZIePxuH1%2FmQyJTM39R1zdWhOyXJ%2FYY9vym0RH%2B6N2XDyxAOl2a6FStAeHcxd8%2BEHmDB3U6AfX2p1wOP5m4ORj2fLd9gFd%2F08e%2F3VZepCr6cRe5ynGF40OnoZjvNjQLzEz2mAL0LFvio2ps42GEOHJ%2FmWRHXKicx9SoOAosEABeRbJPjzKqeatllJgiHlMCoCXIAEWe5DVT%2Fdq3sQcNxHYIfX7lU1LQAF0AXrhI7j58BJQa8952ca9uTN2qZNEwGGuHstUqmFPlv9%2B0hdOAIBvBeBsOPN9CHL8lg1k34I9WMV2QKe7mOY%2BjF%2FAgRvGCtiBVrIndSP5j6HKYRx%2Fkkm9BnSAnBMNu0gT%2B%2FjiMSBmMVxoysGwPqG%2Ft0CYe4j6Qv%2F1unRD%2F%2Be6taVvVcTEfAbS1MgN8qMVVh7mEVWGpK0mJwS%2BY%2BGssfDG3rafoSfnFdStbMFJMgK35ezozVwsnn5cQK9RhPwb4uELaid9jkY7OphLmOzwJLwhhk3entqiZkA9RQ%2B0azOlJODSlC1y5pVcwAmaufpkXAYrlTYThSczMdmG%2BtJLN9pwiqR7eBdNLOl1owWRK37yj0ok%2BYvnta9A5u3sFPD6FxIfNrtEmHW90PqfREVHlQiX8YjzEunreep%2BGyI6IQfeqOiEl0CTSefCXpwh6SVMTfrlVCYEuR%2B1C5AIuNvz3dX0mrF2XGsYrXs8K4FIEA8ypbZsYGjrtFvdXYDwInEWA7%2BHyDJjDJI00w3N6tzgY6mAHMSmoLsoL4KOle99Kh2N5PJiNOx9LJ59nUMBxoXM%2B9PsWsWRQ5m%2BttHEYkjp%2BAT6TCmMyYoiIK50FHMFKBlqh1aAA0ZvjCatk3QNIa%2BqUlUh7jjM2WxBZs%2FX2r%2FGVmhRPz8DUIJ7yzCCirqkexK%2ByOiOulSGuhnsQ19fI9fSms20nb8IRmxWKUdCbscQ6%2Fn8%2BRAMfZkEgMaw%3D%3D&amp;Expires=1774942347\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The implant supports five message types:\u00a0<code>DATA<\/code>\u00a0for forwarding traffic,\u00a0<code>CONNECT<\/code>\u00a0to open a new TCP connection to an internal target,\u00a0<code>CONNECTED<\/code>\u00a0to confirm a session is ready,\u00a0<code>CLOSE<\/code>\u00a0to end a channel, and\u00a0<code>ERROR<\/code>\u00a0to report failures back to the operator. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh_yVMDcj4eZYw5h9eRFXZpZrIqJzfzx3tFzAQ63fhw8KtwcDjr5CxhHNtgij-B-wJbnfxfOroC1eSyXbV6elr38wUhZUppCal13nbvF4p0nU8DsPVRZXjJ1ZAIGMFinKb4ZaJRLIIiGgmQFL6hbjBw5FwsEj1DnVfO-sJO87KMFR622bftEEUMMdFDflw\/s16000\/Importing%2520the%2520net%2520and%2520ws%2520Modules%2520%28Source%2520-%2520BlackPoint%29.webp?ssl=1\" alt=\"Defining message types for this custom protocol (Source - BlackPoint)\"><figcaption class=\"wp-element-caption\">Defining message types for this custom protocol (Source \u2013 BlackPoint)<\/figcaption><\/figure>\n<\/div>\n<p>Together, these types give the attacker dynamic control over which internal systems the compromised host connects to, and all of this activity travels over standard outbound WebSocket traffic, making it difficult to flag with conventional <a href=\"https:\/\/cybersecuritynews.com\/postgresql-monitoring-tools\/\" id=\"37526\" target=\"_blank\" rel=\"noreferrer noopener\">monitoring tools<\/a> alone.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/27023515-47e0-4556-afa8-4d1a5993ea71\/Hackers-Deploy-RoadK1ll-Pivoting-Malware-to-Turn-Compromised-Hosts-Into-Network-Relays.pdf?AWSAccessKeyId=ASIA2F3EMEYEUNUJDHQ2&amp;Signature=gXWTaZvAZ3wWXTpHs9FVlpCIlxU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEG8aCXVzLWVhc3QtMSJHMEUCIQCViPYOrFybj8kwoh1d0IIJz0imxHejYFYIQl7bKdTY1AIgf2Lm9ltrus0fTttCZXuiYxy8E4AKidP8uglvSb7A1Cwq8wQIOBABGgw2OTk3NTMzMDk3MDUiDLSpIo6A2YmpovT7kirQBOwtbeJEMhj8kQ5X%2BcAzReY26fgt1r7QbBv%2FiKIf%2FelbYZIePxuH1%2FmQyJTM39R1zdWhOyXJ%2FYY9vym0RH%2B6N2XDyxAOl2a6FStAeHcxd8%2BEHmDB3U6AfX2p1wOP5m4ORj2fLd9gFd%2F08e%2F3VZepCr6cRe5ynGF40OnoZjvNjQLzEz2mAL0LFvio2ps42GEOHJ%2FmWRHXKicx9SoOAosEABeRbJPjzKqeatllJgiHlMCoCXIAEWe5DVT%2Fdq3sQcNxHYIfX7lU1LQAF0AXrhI7j58BJQa8952ca9uTN2qZNEwGGuHstUqmFPlv9%2B0hdOAIBvBeBsOPN9CHL8lg1k34I9WMV2QKe7mOY%2BjF%2FAgRvGCtiBVrIndSP5j6HKYRx%2Fkkm9BnSAnBMNu0gT%2B%2FjiMSBmMVxoysGwPqG%2Ft0CYe4j6Qv%2F1unRD%2F%2Be6taVvVcTEfAbS1MgN8qMVVh7mEVWGpK0mJwS%2BY%2BGssfDG3rafoSfnFdStbMFJMgK35ezozVwsnn5cQK9RhPwb4uELaid9jkY7OphLmOzwJLwhhk3entqiZkA9RQ%2B0azOlJODSlC1y5pVcwAmaufpkXAYrlTYThSczMdmG%2BtJLN9pwiqR7eBdNLOl1owWRK37yj0ok%2BYvnta9A5u3sFPD6FxIfNrtEmHW90PqfREVHlQiX8YjzEunreep%2BGyI6IQfeqOiEl0CTSefCXpwh6SVMTfrlVCYEuR%2B1C5AIuNvz3dX0mrF2XGsYrXs8K4FIEA8ypbZsYGjrtFvdXYDwInEWA7%2BHyDJjDJI00w3N6tzgY6mAHMSmoLsoL4KOle99Kh2N5PJiNOx9LJ59nUMBxoXM%2B9PsWsWRQ5m%2BttHEYkjp%2BAT6TCmMyYoiIK50FHMFKBlqh1aAA0ZvjCatk3QNIa%2BqUlUh7jjM2WxBZs%2FX2r%2FGVmhRPz8DUIJ7yzCCirqkexK%2ByOiOulSGuhnsQ19fI9fSms20nb8IRmxWKUdCbscQ6%2Fn8%2BRAMfZkEgMaw%3D%3D&amp;Expires=1774942347\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Security teams should closely monitor endpoints for unexpected Node.js processes maintaining persistent outbound WebSocket connections to unfamiliar external addresses. <\/p>\n<p>Outbound traffic to unknown IPs on non-standard ports should be reviewed and blocked where appropriate. Network segmentation controls should be regularly validated to ensure that a compromised host cannot freely reach sensitive internal services. <\/p>\n<p>The known indicators of compromise for RoadK1ll include the file\u00a0<code>Index.js<\/code>, SHA256 hash\u00a0<code>b5a3ace8dc6cc03a5d83b2d85904d6e1ee00d4167eb3d04d4fb4f793c9903b7e<\/code>, and confirmed C2 IP address\u00a0<code>45[.]63[.]39[.]209<\/code>.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/27023515-47e0-4556-afa8-4d1a5993ea71\/Hackers-Deploy-RoadK1ll-Pivoting-Malware-to-Turn-Compromised-Hosts-Into-Network-Relays.pdf?AWSAccessKeyId=ASIA2F3EMEYEUNUJDHQ2&amp;Signature=gXWTaZvAZ3wWXTpHs9FVlpCIlxU%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEG8aCXVzLWVhc3QtMSJHMEUCIQCViPYOrFybj8kwoh1d0IIJz0imxHejYFYIQl7bKdTY1AIgf2Lm9ltrus0fTttCZXuiYxy8E4AKidP8uglvSb7A1Cwq8wQIOBABGgw2OTk3NTMzMDk3MDUiDLSpIo6A2YmpovT7kirQBOwtbeJEMhj8kQ5X%2BcAzReY26fgt1r7QbBv%2FiKIf%2FelbYZIePxuH1%2FmQyJTM39R1zdWhOyXJ%2FYY9vym0RH%2B6N2XDyxAOl2a6FStAeHcxd8%2BEHmDB3U6AfX2p1wOP5m4ORj2fLd9gFd%2F08e%2F3VZepCr6cRe5ynGF40OnoZjvNjQLzEz2mAL0LFvio2ps42GEOHJ%2FmWRHXKicx9SoOAosEABeRbJPjzKqeatllJgiHlMCoCXIAEWe5DVT%2Fdq3sQcNxHYIfX7lU1LQAF0AXrhI7j58BJQa8952ca9uTN2qZNEwGGuHstUqmFPlv9%2B0hdOAIBvBeBsOPN9CHL8lg1k34I9WMV2QKe7mOY%2BjF%2FAgRvGCtiBVrIndSP5j6HKYRx%2Fkkm9BnSAnBMNu0gT%2B%2FjiMSBmMVxoysGwPqG%2Ft0CYe4j6Qv%2F1unRD%2F%2Be6taVvVcTEfAbS1MgN8qMVVh7mEVWGpK0mJwS%2BY%2BGssfDG3rafoSfnFdStbMFJMgK35ezozVwsnn5cQK9RhPwb4uELaid9jkY7OphLmOzwJLwhhk3entqiZkA9RQ%2B0azOlJODSlC1y5pVcwAmaufpkXAYrlTYThSczMdmG%2BtJLN9pwiqR7eBdNLOl1owWRK37yj0ok%2BYvnta9A5u3sFPD6FxIfNrtEmHW90PqfREVHlQiX8YjzEunreep%2BGyI6IQfeqOiEl0CTSefCXpwh6SVMTfrlVCYEuR%2B1C5AIuNvz3dX0mrF2XGsYrXs8K4FIEA8ypbZsYGjrtFvdXYDwInEWA7%2BHyDJjDJI00w3N6tzgY6mAHMSmoLsoL4KOle99Kh2N5PJiNOx9LJ59nUMBxoXM%2B9PsWsWRQ5m%2BttHEYkjp%2BAT6TCmMyYoiIK50FHMFKBlqh1aAA0ZvjCatk3QNIa%2BqUlUh7jjM2WxBZs%2FX2r%2FGVmhRPz8DUIJ7yzCCirqkexK%2ByOiOulSGuhnsQ19fI9fSms20nb8IRmxWKUdCbscQ6%2Fn8%2BRAMfZkEgMaw%3D%3D&amp;Expires=1774942347\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-deploy-roadk1ll-pivoting-malware\/\">Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-deploy-roadk1ll-pivoting-malware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays A new piece of malware called RoadK1ll has been found silently converting compromised machines into controllable network relay points. Unlike most malware that arrives loaded with commands and attack tools, RoadK1ll is deliberately lean, built around one goal: giving attackers a reliable and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-11738","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11738"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11738"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11738\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11738"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11738"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11738"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}