Mocha Manakin is a threat activity cluster identified in 2025 and associated with paste-and-run social-engineering campaigns, also known as ClickFix or fakeCAPTCHA. The cluster relies on lures that trick users into manually executing attacker-supplied commands, typically through the Windows Run dialog or PowerShell, to establish initial access. It is distinguished from other paste-and-run clusters by the deployment of a bespoke Node.js backdoor named NodeInitRAT. After user execution of the staged command, Mocha Manakin delivers follow-on payloads and installs NodeInitRAT, which provides persistence, host and domain reconnaissance, arbitrary command execution, and the ability to deploy additional payloads. Reported behavior includes enumeration of principal names and domain details, HTTP-based command-and-control communications, and use of intermediary tunneling infrastructure to mask backend systems. The cluster’s tradecraft aligns with broader post-compromise objectives rather than simple commodity malware delivery alone. Mocha Manakin has been linked to overlaps with Interlock ransomware reporting, including shared use of paste-and-run initial access, delivery of a Node.js remote access tool, and some infrastructure commonalities. Some infections attributed to Mocha Manakin have reportedly served as initial access points for Interlock ransomware operations. Although direct progression from Mocha Manakin activity to ransomware was not consistently observed in the reporting, the cluster is assessed as likely to support downstream ransomware intrusion activity. Known associated tooling and malware include NodeInitRAT, and reporting places the cluster within the broader ecosystem of socially engineered initial-access operations that frequently lead to hands-on-keyboard post-exploitation. No high-confidence attribution to a nation state or specific country of origin is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Observed in paste-and-run campaigns as a delivered threat associated with malicious copy-and-paste initial access lures.
Uses supply chain and social engineering techniques to deliver custom Node.js backdoors for persistence and reconnaissance.
Initial access / malware delivery actor using ClickFix lures to deploy a custom NodeJS backdoor (NodeInitRAT); resulting footholds sometimes leveraged as initial access for Interlock ransomware operations.
Activity cluster leveraging the “paste and run” (Clickfix/fakeCAPTCHA) initial access technique to trick users into executing obfuscated PowerShell that downloads follow-on payloads. Post-compromise activity includes deployment of a bespoke NodeJS backdoor (NodeInitRAT) for persistence and reconnaissance, with C2 over HTTP often via Cloudflare tunnels; assessed as likely to lead to ransomware if unmitigated.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.