NodeSnake is a multi-implementation remote access trojan and persistent access backdoor associated with the Interlock ransomware operation, also tracked in connection with Hive0163. It has been observed as an early-stage component in Interlock intrusion chains and is used to establish footholds, execute commands, maintain persistence, and retrieve or launch follow-on payloads including InterlockRAT and, in broader campaigns, ransomware tooling. Security reporting has also described NodeSnake as serving as the first-stage loader in many Interlock infections, reflecting its role in both access maintenance and staged payload delivery.
The malware family has been documented in several forms, including a JavaScript variant for Node.js, Java JAR variants, and native C++ binaries. Across these implementations, NodeSnake exhibits a shared command-and-control design and host profiling logic. Reported capabilities include remote shell access, one-shot command execution, file transfer, self-update, self-deletion, operator-controlled sleep and disconnect behavior, and SOCKS5 proxying. Native variants add more advanced functionality such as TCP tunneling, anti-debugging checks, DLL execution through system utilities, thread execution hijacking, and privilege-aware behavior. More recent activity has also been linked to a screenshot collection module, indicating ongoing development.
NodeSnake has been repeatedly linked to ClickFix-style social engineering campaigns in which victims are tricked into executing malicious PowerShell commands, after which the malware is downloaded and installed. It has also been associated with trojanized software installers and broader traffic-distribution-driven delivery ecosystems used by Interlock operators and related access brokers. Campaign reporting ties NodeSnake activity to sectors including education, with deployments observed on networks of U.K. universities, and to wider ransomware targeting of healthcare, government, and enterprise environments.
Code, infrastructure, and behavioral overlaps connect NodeSnake with other malware used in the Interlock ecosystem, including InterlockRAT, JunkFiction, Supper, and ModeloRAT. These overlaps have been assessed as evidence of a shared development pipeline or closely cooperating operators. In practice, NodeSnake functions as a durable access layer within a larger extortion and ransomware framework, enabling post-compromise operations, follow-on tooling deployment, and progression toward data theft and ransomware execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Interlock ransomware gang has been exploiting a maximum severity remote code execution (RCE) vulnerability in Cisco's Secure Firewall Management Center (FMC) software in zero-day attacks since late January. Cisco patched the security flaw (CVE-2026-20131) on March 4, warning that it could allow unauthenticated attackers to remotely execute arbitrary Java code as root on unpatched devices.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Beginning in early July 2026, the Blackpoint APG has identified the NodeSnake RAT being deployed again, with more than 5 incidents in the previous 14 days.
"The Interlock ransomware group has deployed a previously undocumented JavaScript remote access trojan called NodeSnake..."
The attack in itself is said to have leveraged the ClickFix social engineering tactic to trick the victim into running a PowerShell command, which then downloads NodeSnake, a known malware attributed to Hive0163. A first-stage component, NodeSnake, is designed to run shell commands, establish persistence, and retrieve and launch a wider malware framework referred to as Interlock RAT.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The Interlock ransomware operation surfaced in September 2024 and has been linked to ClickFix and to malware attacks in which they deployed a remote access trojan called NodeSnake on the networks of multiple U.K. universities.
The Java variant adds two features... The UpdateThread creates a self-deleting scheduled task... Like the Java variant, the PE uses self-deleting scheduled tasks... A daily scheduled task runs the ransomware at 20:00 as SYSTEM.
The attack in itself is said to have leveraged the ClickFix social engineering tactic to trick the victim into running a PowerShell command, which then downloads NodeSnake.
Thread execution hijacking : uses SetThreadContext / GetThreadContext to inject into running threads.
DELETE 0x0c fs.rmSync(__filename)... If the counter passes 40, the implant deletes itself... self-deleting scheduled task... --delete (self-delete after encryption)
The PowerShell script functions as a full-fledged backdoor that can beacon a heartbeat message containing system information to a C2 server every 30 seconds, poll for a new command every 50 seconds, execute it via "cmd.exe," and relay the results back to the server.
The implant connects over ws:// and rotates across nine Cloudflare Tunnel domains plus three fallback IP addresses... All three tiers use the same transport protocol... RC4-encrypted WebSocket framing.
Operator commands. The implant supports 12 message types: SOCKS5 0x05 SOCKS5 proxy... The native implant runs a multi-threaded design: SocksThread SOCKS4 proxy handler Socks5Thread SOCKS5 proxy handler
The C2 infrastructure runs through free Cloudflare Tunnel endpoints as disposable WebSocket relays, falling back to hardcoded IPs on hosting providers.
The native variant adds several features not present in the scripted tiers: TCP tunnel relay (TcpTunnel): forwards arbitrary TCP connections through the implant, allowing the operator to reach internal hosts.
Once inside, attackers use traffic distribution systems to redirect victims and deliver payloads through ClickFix-style attacks or fake browser updates. | NodeSnake, which acts as the first stage loader in most Interlock infections, shares code logic and server addresses with both JunkFiction downloader and InterlockRAT.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan tied in the content to the Interlock Ransomware operation, delivered via ClickFix-style attacks and described as evolving with a new screenshot collection module.
A first-stage loader used in most Interlock infections. It shares code logic and infrastructure with JunkFiction and InterlockRAT, and its code structure was later extended by ModeloRAT.
WebSocket-based persistent backdoor implemented in JavaScript, Java, and native C++. It uses RC4-encrypted message framing, Cloudflare Tunnel and hardcoded IPs for C2, profiles hosts, supports SOCKS proxying, command execution, file transfer, self-update, and in the native PE variant adds TCP tunnelling, thread execution hijacking, anti-debugging, and DLL execution.
A remote access trojan deployed by Interlock on the networks of multiple U.K. universities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.