Interlock ransomware gang deploys new NodeSnake RAT on universities
ID: 6c8e4e5d-0caf-5c78-9f92-9f5fa56ab5e6
STIX ID: report--6c8e4e5d-0caf-5c78-9f92-9f5fa56ab5e6
Feed Name: Bleeping Computer
Threat Score
Interlock ransomware operators are using a newly observed NodeSnake RAT (NodeJS-based) against UK universities via phishing, establishing stealthy persistence (fake 'ChromeUpdater' registry key), evading detection with heavy obfuscation and Cloudflare-proxied C2, and enabling reconnaissance, command execution, payload loading, and data exfiltration; multiple divergent samples indicate active development and QuorumCyber provides full IoCs for detection and blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
