#CheckPoint Research analyzed #GachiLoader, a Node.js–based #malware loader observed in a campaign linked to the #YouTube #GhostNetwork. The campaign is notable for extensive obfuscation and a previously undocumented PE injection technique. GachiLoader deploys a second-stage loader, #Kidkadi, which abuses Vectored Exception Handling (VEH) in a novel method, dubbed Vectored Overloading.

https://research.checkpoint.com/2025/gachiloader-node-js-malware-with-api-tracing/

GachiLoader: Defeating Node.js Malware with API Tracing GachiLoader: Defeating Node.js Malware

Check Point Research exposes GachiLoader, a Node.js loader in the YouTube Ghost Network, and shows how API tracing defeats its obfuscation.

Check Point Research

“he was trapped in what’s commonly known as a “ghost network.” Many of the mental health providers that Ambetter listed as accepting its insurance were not actually able to see him.”
#DenyDefendDepose #GhostNetwork #HealthcareInsurance #HealrhcareForProfit

https://www.propublica.org/article/centene-ghost-network-lawsuit-ambetter-ravi-coutinho

He Died Without Getting Mental Health Care He Sought. A New Lawsuit Says His Insurer’s Ghost Network Is to Blame.

The mother of Ravi Coutinho, the subject of a recent ProPublica investigation, is suing Centene for publishing “misleading” information that gave her son a false impression about the kinds of mental health care that were actually available.

ProPublica