The Interlock ransomware gang is escalating its activity, developing a new remote access trojan (RAT ) called NodeSnake , this time targeting the higher education sector (universities).

According to analysis by QuorumCyber, NodeSnake was detected in at least two confirmed attacks on UK universities in January and March 2025. The two samples showed significant differences between them, suggesting that the malware is under active development, with new features and capabilities being added.
The Interlock group emerged in September 2024 and has been linked to attacks against Texas Tech University , DaVita , and Kettering Health in Ohio. In addition, the group has used “ClickFix ” tactics , posing as malicious files as technical support tools, to gain initial penetration into corporate networks.
See also: DragonForce ransomware abuses SimpleHelp
NodeSnake : A new RAT malware from the Interlock ransomware gang
NodeSnake RAT is mainly distributed through phishing campaigns , with messages containing malicious links or attachments, which lead to the infection of systems.
The malware is written in JavaScript and runs via the Node.js runtime. It achieves a persistent presence on the infected system using PowerShell or CMD scripts that create deceptive registry entries, such as “ChromeUpdater,” which pretends to be related to Google Chrome updates — a technique that helps the malware go unnoticed by users and security systems.
To avoid detection, the malware runs as a detached background process and the filenames and payloads are given random names. In addition, communications with C2 servers are performed with random time delays, further reducing the likelihood of detection by security systems.
See also: Iranian man confesses to involvement in Robbinhood ransomware
The malicious code is heavily obfuscated, uses XOR encryption with rolling keys and random seeds, and also applies console tampering to confuse debugging tools.
Although the C2 IP address is hardcoded, the connection is routed through Cloudflare-proxied domains, masking the true identity of the attacker's infrastructure.

Spying and remote control capabilities
Once activated, the NodeSnake malware collects sensitive metadata , such as user information, running processes, active services, and network settings. The data is sent back to the Interlock ransomware gang's servers
Its functionality doesn't stop there. The malware can terminate processes , load additional EXE , DLL or JavaScript files , as well as execute CMD commands in real time .
Persistence and early detection
The existence and continued improvement of NodeSnake is a clear indication of Interlock’s intention to maintain long-term access to critical networks. The full list of indicators of compromise (IoCs) is available at the end of the QuorumCyber report and can prove extremely useful for early detection and prevention of ransomware attacks.
Early monitoring of these indicators is critical, as it can prevent data extraction and encryption — the final and most devastating phases of an Interlock attack.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: MathWorks: Ransomware attack behind service outage
Recommendations for protection:
- Stay up to date on the latest ransomware trends and tactics used by attackers
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using solutions email security for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Enable the display of file extensions
- Invest in advanced protection solutions
- Use sandboxing for email attachments
- Keep backup copies of your data
Source: www.bleepingcomputer.com
