NodeInitRAT is a bespoke Node.js-based remote access trojan/backdoor associated with the Mocha Manakin activity cluster. It has been observed in attacks beginning in January 2025 and is delivered after ClickFix / paste-and-run / fakeCAPTCHA social-engineering lures that trick users into executing an obfuscated PowerShell command. Red Canary describes NodeInitRAT as the distinguishing payload in Mocha Manakin intrusions.
Its documented capabilities include establishing persistence, performing reconnaissance, enumerating principal names, gathering domain details, executing arbitrary commands, and deploying additional payloads on compromised systems. The malware communicates with adversary-controlled servers over HTTP and often uses Cloudflare tunnels as intermediary infrastructure.
NodeInitRAT has been linked to Mocha Manakin, and reporting notes overlaps with Interlock ransomware activity, including shared use of paste-and-run initial access, delivery of a Node.js RAT, and some shared infrastructure. Some infections involving NodeInitRAT have reportedly been used as initial access entry points by the Interlock ransomware gang. As of May 2025, Red Canary had not directly observed Mocha Manakin activity progress to ransomware, but assessed with moderate confidence that unmitigated intrusions are likely to lead to ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Red Canary has spotted a new threat actor group named Mocha Manakin. The group uses ClickFix campaigns to deploy a custom NodeJS-based backdoor named NodeInitRAT. Some of its infections have been used as initial access entry points by the Interlock ransomware gang.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
NodeInitRAT is a Node.js-based remote access trojan/backdoor that enables persistence, reconnaissance, command execution, and payload deployment. It is linked to attacks using ClickFix and overlaps with tooling used in Interlock ransomware campaigns.
Custom NodeJS-based backdoor/RAT deployed via ClickFix-style social engineering, used to establish remote access and serve as an initial access foothold (including for subsequent ransomware activity).
A bespoke NodeJS-based remote access trojan/backdoor used post-compromise to establish persistence, perform reconnaissance (e.g., enumerating principal names and gathering domain details), communicate over HTTP (often via Cloudflare tunnels), execute arbitrary commands, and deploy additional payloads.
NodeJS backdoor deployed following the Mocha Manakin paste-and-run activity cluster.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.