Last seven days
- First activity
- Aug 31, 2026
- Last activity
- Aug 31, 2026
- Feed role
- C2
- Host form
- 0 IP / 3 hostnames
NOVABLIGHT is a NodeJS- and Electron-based Malware-as-a-Service (MaaS) information stealer.
Profile source: Mallory opens in a new tabNOVABLIGHT
NOVABLIGHT is a NodeJS- and Electron-based Malware-as-a-Service (MaaS) information stealer. It is described as modular, heavily obfuscated, and feature-rich, with capabilities extending beyond credential theft. Reported functionality includes theft of login credentials, cryptocurrency wallet data, Chromium-based browser data, Wi-Fi passwords, screenshots, running process lists, antivirus details, clipboard contents, webcam video, and files matching sensitive keywords. It also includes a clipboard hijacker that replaces cryptocurrency or PayPal addresses with attacker-controlled values, and can inject malicious code into Electron applications such as Discord, Exodus, Mullvad VPN, Atomic Wallet, and Mailspring by unpacking and repacking ASAR files.
The malware performs anti-analysis and anti-debugging checks, including inspection of GPU names, usernames, VM drivers, screen resolution, USB presence, and remote GitHub-hosted blacklists, and can terminate known analysis and debugging tools based on a remotely hosted list. Additional sabotage and defense-evasion behavior reported for NOVABLIGHT includes attempts to disable Windows Defender via a downloaded batch file, disable Task Manager via the registry, repeatedly disable Wi-Fi and Ethernet adapters, disable the Windows Recovery Environment, delete Volume Shadow Copies, make its own executable undeletable with icacls, and remove the current user from local privileged groups.
NOVABLIGHT is sold as a MaaS offering through Telegram, Discord, and commercial storefronts, with customers purchasing time-limited API keys to generate malware builds via Telegram bot or Discord. Operators also provide a dashboard for viewing stolen victim data and support multiple exfiltration channels, including a proprietary panel, Telegram, Discord webhooks, and third-party file-hosting services such as bashupload, catbox, tmpfiles, oshi, sendfile, wsend, gofile, rdmfile, and bamboulacity.nova-blight[.]xyz/file/. Distribution has been observed through fake video game installers, including a lure site at gonefishe[.]com presenting a French-language game installer.
The operators are assessed in the cited reporting as likely being the French-speaking Sordeal Group, with links noted to Nova Sentinel and MALICORD. Mentioned NOVABLIGHT-related infrastructure includes api.nova-blight[.]top, shadow.nova-blight[.]top, nova-blight[.]site, nova-blight[.]xyz, and bamboulacity.nova-blight[.]xyz.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
NOVABLIGHT is a NodeJS-based Malware-as-a-Service (MaaS) information stealer developed and sold by a threat group that demonstrates French-language proficiency.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.