[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-mB30ovI9qJaWu8D-bniXBII5O1LrenXWFbZ7tfUKTw":3},{"article":4,"iocs":36,"watch_terms":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":10,"url":11,"image_url":10,"published_at":12,"ingested_at":13,"relevance_score":14,"entities":15,"category_id":16,"category":17,"article_tags":20},"d6a9bd6e-a951-45b4-9082-8251a8dc4627","The Flow: A fake \"Verify You Are Human\" prompt leads to Node.js C2 (interlock RAT), followed by h...","the-flow-a-fake-verify-you-are-human-prompt-leads-to-node-js-c2-interlock-rat-fo","The Flow: A fake \"Verify You Are Human\" prompt leads to Node.js C2 (interlock RAT), followed by hands-on-keyboard activity where they use vol.exe from \\AppData\\Local\\Temp\\ to harvest credentials.","A social engineering campaign uses fake CAPTCHA prompts to distribute Interlock RAT, a Node.js-based command-and-control malware. After establishing C2 communication, attackers perform hands-on-keyboard activity using Volatility tools to dump credentials from memory.",null,"https:\u002F\u002Fx.com\u002FTheDFIRReport\u002Fstatus\u002F2034680674645311839","2026-03-19T17:17:30+00:00","2026-03-19T18:00:19.175753+00:00",8,[],"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":16,"icon":10,"name":18,"slug":19},"Malware","malware",[21,26,31],{"category":22},{"id":23,"icon":10,"name":24,"slug":25},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":27},{"id":28,"icon":10,"name":29,"slug":30},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":32},{"id":33,"icon":10,"name":34,"slug":35},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[37,40],{"type":19,"value":38,"context":39},"Interlock RAT","Node.js-based remote access trojan deployed via fake CAPTCHA prompts",{"type":19,"value":41,"context":42},"vol.exe","Volatility memory analysis tool used by attackers for credential harvesting from AppData\\Local\\Temp",[]]