Malware
GootKit
aka Waldek · Xswkit · talalpek
Gootkit is a banking trojan consisting of an x86 loader and a payload embedding nodejs as well as a set of js scripts.
GootKit, also known as Waldek, Xswkit, talalpek, is a Windows malware family.
Background
Gootkit is a banking trojan built from an x86 loader paired with a payload that bundles nodejs together with a collection of js scripts. The loader retrieves the payload, saves it in the registry, and injects it into a copy of its own process. It also carries two encrypted DLLs meant to be injected into every launched browser process, establishing man-in-the-browser positioning so that webinjects fetched from the command-and-control server can be applied to HTTPx exchanges. Through this, Gootkit can intercept HTTPx requests and responses to steal their contents or alter them in line with the webinjects.
Source: Malpedia (Fraunhofer FKIE).