JunkFiction is a custom malware loader and downloader associated with the financially motivated Interlock ransomware operation, tracked as Hive0163. It delivers additional malicious payloads on Windows systems, including the Supper backdoor and the 64-bit Windows Interlock ransomware executable. In a November 2024 Interlock-linked intrusion, JunkFiction downloaded and deployed a Supper backdoor protected by the JunkFiction crypter.
JunkFiction belongs to a private toolset that also includes NodeSnake and InterlockRAT. The downloader shares code logic and command-and-control server infrastructure with those families. Its role is payload delivery within a broader intrusion chain, rather than the ransomware encryption performed by Interlock. The JunkFiction name is also used for a crypter that protects Supper and other Interlock-associated malware; that packing role is distinct from the loader's delivery function.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Local privilege escalation exploit CVE-2023-36036 (JunkFiction-crypted) ... CVE CVE-2023-36036 Local privilege escalation exploit used by Interlock and ModeloRAT operators
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The e-crime group is primarily associated with a wide range of malicious tools, including NodeSnake, Interlock RAT, JunkFiction loader, and Interlock ransomware.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Once inside, attackers use traffic distribution systems to redirect victims and deliver payloads through ClickFix-style attacks or fake browser updates. | NodeSnake, which acts as the first stage loader in most Interlock infections, shares code logic and server addresses with both JunkFiction downloader and InterlockRAT.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A downloader used by Interlock and seen in Rhysida infection chains. It is also used as a crypter/protector for other payloads, including Supper and Interlock ransomware binaries.
The name is used for a downloader and for protection applied to Supper backdoor samples. The downloader deployed the protected backdoor in a November 2024 Interlock-linked incident.
Loader used by Hive0163 as part of its custom toolkit to help establish and maintain long-term access in compromised environments.
Loader used to deploy the Interlock ransomware payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.