A new malware has infected thousands of Windows computers around the world. The software installs a copy of the Node.js framework with the aim of turning systems into proxies and committing click-fraud . Microsoft had talked about this software in a report . It calls it Nodersok . Cisco Talos, on the other hand, calls it Divergent . It was discovered in the summer and was distributed through malicious ads that downloaded HTA (HTML application) files to victims' computers 
The execution of the HTA files resulted in the initiation of a multi-level system infection process. The infection process affected Excel, JavaScript, and PowerShell. The final stage was the download and installation of Nodersok.
The malware has many features, which serve different purposes. There is a PowerShell function that aims to disable Windows Defender and Windows Update.
There are also two features that are legitimate applications. They are called WinDivert and Node.js.WinDivert allows for the reception and interaction of network. Node.js is a well-known tool for running JavaScript on web servers.
The malware uses both applications to launch a SOCKS proxy on infected computers. However, Microsoft and Cisco have different views on what exactly is happening. Microsoft claims that Nodersok turns infected computers into proxies to perform malicious activity. Cisco says that these proxies are used to commit click fraud.

Either way, Nodersok administrators can leverage the software to perform additional malicious functions or deploy secondary payloads, such as ransomware or banking trojans.
One way for users is to not run HTA files they find on their computers, especially if their origin is unknown. Finding files downloaded from the Internet is a bad sign.
According to reports, Nodersok has already infected thousands of computers in just a few weeks. Most of the attacks took place in September and mainly affected users in Europe and America.
The fact that Nodersok uses legitimate applications and in-memory payloads makes detecting its infections very difficult.
Cisco Talos researchers say that the malware is still in development. Nodersok's administrators aim to earn as much money as possible through click fraud. Therefore, the malware will be of concern to security for a long time to come.
