Trojan.Waldek, according to Kaspersky, is a Trojan written in JavaScript (JS) and running in the context of Node.js, which allows running JS code outside of a browser. This Trojan is usually downloaded by another loader called Trojan-Downloader.Win32.Gootkit which is distributed via the Angler EK exploit pack. Trojan.Waldek can be multifunctional since it is designed with a modular architecture, which enables it to steal banking information and do other harmful things, such as taking screenshots, getting a list of running processes, stopping a process, starting VNC access, and performing web injects, accessing the file system, and running batch commands.











