Skip to content

NOVABLIGHT

NOVABLIGHT is a NodeJS- and Electron-based Malware-as-a-Service (MaaS) information stealer.

Profile source: Mallory opens in a new tab

NOVABLIGHT

Family profile

NOVABLIGHT is a NodeJS- and Electron-based Malware-as-a-Service (MaaS) information stealer. It is described as modular, heavily obfuscated, and feature-rich, with capabilities extending beyond credential theft. Reported functionality includes theft of login credentials, cryptocurrency wallet data, Chromium-based browser data, Wi-Fi passwords, screenshots, running process lists, antivirus details, clipboard contents, webcam video, and files matching sensitive keywords. It also includes a clipboard hijacker that replaces cryptocurrency or PayPal addresses with attacker-controlled values, and can inject malicious code into Electron applications such as Discord, Exodus, Mullvad VPN, Atomic Wallet, and Mailspring by unpacking and repacking ASAR files.

The malware performs anti-analysis and anti-debugging checks, including inspection of GPU names, usernames, VM drivers, screen resolution, USB presence, and remote GitHub-hosted blacklists, and can terminate known analysis and debugging tools based on a remotely hosted list. Additional sabotage and defense-evasion behavior reported for NOVABLIGHT includes attempts to disable Windows Defender via a downloaded batch file, disable Task Manager via the registry, repeatedly disable Wi-Fi and Ethernet adapters, disable the Windows Recovery Environment, delete Volume Shadow Copies, make its own executable undeletable with icacls, and remove the current user from local privileged groups.

NOVABLIGHT is sold as a MaaS offering through Telegram, Discord, and commercial storefronts, with customers purchasing time-limited API keys to generate malware builds via Telegram bot or Discord. Operators also provide a dashboard for viewing stolen victim data and support multiple exfiltration channels, including a proprietary panel, Telegram, Discord webhooks, and third-party file-hosting services such as bashupload, catbox, tmpfiles, oshi, sendfile, wsend, gofile, rdmfile, and bamboulacity.nova-blight[.]xyz/file/. Distribution has been observed through fake video game installers, including a lure site at gonefishe[.]com presenting a French-language game installer.

The operators are assessed in the cited reporting as likely being the French-speaking Sordeal Group, with links noted to Nova Sentinel and MALICORD. Mentioned NOVABLIGHT-related infrastructure includes api.nova-blight[.]top, shadow.nova-blight[.]top, nova-blight[.]site, nova-blight[.]xyz, and bamboulacity.nova-blight[.]xyz.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 31, 2026
Last activity
Aug 31, 2026
Feed role
C2
Host form
0 IP / 3 hostnames

Leading locations

  • US3

Leading providers

  • Cloudflare, Inc.2
  • Squarespace, Inc.1

Infrastructure traits

  • Anycast 3
  • Hosting 3

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Sordeal

NOVABLIGHT is a NodeJS-based Malware-as-a-Service (MaaS) information stealer developed and sold by a threat group that demonstrates French-language proficiency.

MITRE ATT&CK

NOVABLIGHT in ATT&CK

20 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.