A sophisticated new group called Mocha Manakinhas emerged in the cybersecurity field, using an increasingly popular social engineering known as paste and runto trick users into executing malicious scripts on their systems.
See also: Russian hackers bypass Gmail MFA

This deceptive method has gained widespread popularity among cybercriminals due to its effectiveness in bypassing traditional security measures and exploiting human psychology instead of technical vulnerabilities.
The “paste and run” technique, also referred to as Clickfix or fakeCAPTCHA, presents users with supposedly valid verification forms, misleading them into believing they need to complete certain steps to gain access to documents, websites, or software installations.
The attack typically involves fake buttons like “Fix” or “Verify”, which secretly copy disguised PowerShell to the user’s clipboard, followed by instructions that guide victims in executing these malicious commands.
Red Canary analysts first detected Mocha Manakin activity in January 2025, distinguishing it from other paste-and-run campaigns thanks to its use of a custom NodeJS-, known as NodeInitRAT.
See also: Hackers claim breach of Scania services
The group has shown persistence and evolution in its tactics, with researchers observing multiple versions of attack orders throughout 2025.

What differentiates Mocha Manakin from similar threats is the complexity of the final malicious payload and the ability to scale into ransomware.
Red Canary researchers have identified commonalities between Mocha Manakin's activity and the Interlock ransomware operations, suggesting that successful infections may ultimately lead to more devastating consequences.
While an immediate transition to ransomware has not yet been observed, security experts estimate with a moderate degree of certainty that if Mocha Manakin activity is not addressed in a timely manner, ransomware development is likely to follow.
See also: Hackers use ClickFix technique to deploy Trojans
A related and worrying element associated with Mocha Manakin attacks is the fact that they rely on social engineering techniques, which do not require advanced hacking techniques. Instead of exploiting “technical vulnerabilities” in software or systems, they rely on tricking the user into executing the malicious code.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
