Researchers reported a ClickFix infection chain delivering a Node.js-based Interlock RAT variant after victims paste and execute a concealed PowerShell command through the Windows Run dialog. The malware downloads a legitimate signed Node.js runtime into the user’s roaming AppData directory and uses it to run a payload masquerading as debug.txt, minimizing suspicious executable artifacts. The campaign establishes raw TCP command-and-control over port 443 and persists through an HKCU\...\Run value named ChromeUpdater.
The Node.js variant fingerprints compromised hosts, supports SOCKS proxying, and performs extensive endpoint and Active Directory reconnaissance, including searches of computer descriptions for likely backup servers. The activity follows earlier reporting that KongTuke FileFix lures also led to a new Interlock RAT variant, indicating that Interlock operators are using multiple social-engineering execution techniques to deploy the malware. Attribution to Interlock is based on its distinctive C2 protocol header and observed behavior; the reports do not identify the keyboard operator.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
CISA, the FBI, HHS, and MS-ISAC issued joint advisory AA25-203A concerning Interlock.
The Interlock double-extortion ransomware operation was first observed.
A ClickFix lure induced a victim to run a concealed PowerShell command via the Windows Run dialog, which downloaded a signed Node.js runtime and executed an Interlock RAT payload stored as debug.txt. The RAT used raw TCP C2 over port 443, established ChromeUpdater HKCU Run-key persistence, and conducted host, Active Directory, and backup-server reconnaissance without observed ransomware encryption.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.