Mocha Manakin is a Red Canary-named activity cluster first tracked in January 2025. It is a paste-and-run initial access cluster, also described as ClickFix or fakeCAPTCHA activity, in which victims are socially engineered into pasting and executing an obfuscated PowerShell command that downloads follow-on payloads from adversary infrastructure. Red Canary described Mocha Manakin as its first named paste-and-run threat cluster and noted it had been tracking several such clusters since August 2024. Mocha Manakin is distinguished from other paste-and-run clusters by deployment of a bespoke NodeJS-based backdoor named NodeInitRAT. NodeInitRAT provides persistence, performs reconnaissance including principal name and domain enumeration, communicates over HTTP, often via Cloudflare tunnels, can execute arbitrary commands, and can deploy additional payloads. Reported overlaps exist with Interlock ransomware-related activity, including shared use of paste-and-run for initial access, delivery of a NodeJS RAT, and some shared infrastructure. Red Canary reported that some Mocha Manakin infections were used as initial access entry points by the Interlock ransomware gang, but as of May 2025 it had not directly observed Mocha Manakin activity progress to ransomware. Red Canary assessed with moderate confidence that unmitigated Mocha Manakin intrusions are likely to lead to ransomware. Known alias in the provided content: mocha_manakin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Observed in paste-and-run campaigns as a delivered threat associated with malicious copy-and-paste initial access lures.
Uses supply chain and social engineering techniques to deliver custom Node.js backdoors for persistence and reconnaissance.
Initial access / malware delivery actor using ClickFix lures to deploy a custom NodeJS backdoor (NodeInitRAT); resulting footholds sometimes leveraged as initial access for Interlock ransomware operations.
Activity cluster leveraging the “paste and run” (Clickfix/fakeCAPTCHA) initial access technique to trick users into executing obfuscated PowerShell that downloads follow-on payloads. Post-compromise activity includes deployment of a bespoke NodeJS backdoor (NodeInitRAT) for persistence and reconnaissance, with C2 over HTTP often via Cloudflare tunnels; assessed as likely to lead to ransomware if unmitigated.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.