HomeSecurityInterlock ransomware: Gang uses new NodeSnake RAT

Interlock ransomware: Gang uses new NodeSnake RAT

The Interlock ransomware gang is escalating its activity, developing a new remote access trojan (RAT ) called NodeSnake , this time targeting the higher education sector (universities).

Interlock ransomware NodeSnake RAT malware

According to analysis by QuorumCyber, NodeSnake was detected in at least two confirmed attacks on UK universities in January and March 2025. The two samples showed significant differences between them, suggesting that the malware is under active development, with new features and capabilities being added.

The Interlock group emerged in September 2024 and has been linked to attacks against Texas Tech University , DaVita , and Kettering Health in Ohio. In addition, the group has used “ClickFix ” tactics , posing as malicious files as technical support tools, to gain initial penetration into corporate networks.

See also: DragonForce ransomware abuses SimpleHelp

NodeSnake : A new RAT malware from the Interlock ransomware gang

NodeSnake RAT is mainly distributed through phishing campaigns , with messages containing malicious links or attachments, which lead to the infection of systems.

The malware is written in JavaScript and runs via the Node.js runtime. It achieves a persistent presence on the infected system using PowerShell or CMD scripts that create deceptive registry entries, such as “ChromeUpdater,” which pretends to be related to Google Chrome updates — a technique that helps the malware go unnoticed by users and security systems.

To avoid detection, the malware runs as a detached background process and the filenames and payloads are given random names. In addition, communications with C2 servers are performed with random time delays, further reducing the likelihood of detection by security systems.

See also: Iranian man confesses to involvement in Robbinhood ransomware

The malicious code is heavily obfuscated, uses XOR encryption with rolling keys and random seeds, and also applies console tampering to confuse debugging tools.

Although the C2 IP address is hardcoded, the connection is routed through Cloudflare-proxied domains, masking the true identity of the attacker's infrastructure.

Interlock ransomware: Gang uses new NodeSnake RAT

Spying and remote control capabilities

Once activated, the NodeSnake malware collects sensitive metadata , such as user information, running processes, active services, and network settings. The data is sent back to the Interlock ransomware gang's servers

Its functionality doesn't stop there. The malware can terminate processes , load additional EXE , DLL or JavaScript files , as well as execute CMD commands in real time .

Persistence and early detection

The existence and continued improvement of NodeSnake is a clear indication of Interlock’s intention to maintain long-term access to critical networks. The full list of indicators of compromise (IoCs) is available at the end of the QuorumCyber ​​report and can prove extremely useful for early detection and prevention of ransomware attacks.

Early monitoring of these indicators is critical, as it can prevent data extraction and encryption — the final and most devastating phases of an Interlock attack.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: MathWorks: Ransomware attack behind service outage

Recommendations for protection:

  • Stay up to date on the latest ransomware trends and tactics used by attackers
  • Implement multi-factor authentication (MFA) for all user accounts
  • Enable firewall on all devices connected to your network
  • Keep sensitive data encrypted
  • Update all your devices and systems with the latest security patches
  • Conduct regular security audits and penetration testing
  • Use strong, unique passwords and change them regularly.
  • Limit user access to only necessary systems and information
  • Consider using solutions email security for additional protection against phishing attacks
  • Have a recovery plan to quickly restore systems in the event of an attack
  • Enable the display of file extensions
  • Invest in advanced protection solutions
  • Use sandboxing for email attachments
  • Keep backup copies of your data

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS