Ransomware, Critical Infrastructure Security

Novel NodeSnake RAT deployed in university-targeted Interlock ransomware intrusions

(Adobe Stock)

BleepingComputer reports that attacks spreading the new NodeSnake remote access trojan have been launched by the Interlock ransomware operation against UK universities in January and March.

Interlock commenced intrusions with the distribution of phishing emails with links or attachments leading to the deployment of the JavaScript-based NodeSnake malware, according to a QuorumCyber analysis. After ensuring persistence via PowerShell or CMD scripts and maintaining stealth through console tampering and XOR encryption, NodeSnake RAT then exfiltrates system metadata, ends active processes, and launches further payloads on targeted devices. Interlock also created an updated version of NodeSnake RAT, which has been improved to allow CMD command execution and the usage of more modules for dynamic C2 polling behavior modifications, indicating ongoing malware development, according to researchers. Such findings come after Interlock, which also harnessed ClickFix attack tactics, was reported to have targeted Ohio-based medical network Kettering Health, dialysis provider DaVita, and the Texas Tech University.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds