Interlock ransomware debuts PHP RAT via FileFix
Interlock ransomware group is using a new PHP-based RAT delivered through KongTuke/LandUpdate808 fake-CAPTCHA web injects and Cloudflare Tunnels for C2.
The DFIR Report, working with Proofpoint, identified a new PHP variant of the Interlock ransomware group's RAT, a departure from the group's earlier Node.js-based Interlock RAT (NodeSnake). The infection chain begins with compromised legitimate websites injected with a hidden single-line script tied to the LandUpdate808/KongTuke web-inject cluster. Victims are lured through a fake "Verify you are human" CAPTCHA and 'FileFix' verification steps that trick them into pasting and executing a malicious PowerShell command via the Windows Run dialog, which retrieves and launches PHP configured to load the RAT payload.
Once executed, the PHP-based Interlock RAT performs extensive automated discovery (system info, running processes/services, mounted drives, ARP neighbors, privilege level) and exfiltrates results as JSON, followed by hands-on-keyboard Active Directory and domain reconnaissance suggesting an interactive operator session. The malware establishes C2 over Cloudflare Tunnel (trycloudflare.com) subdomains with hardcoded fallback IPs for resilience, supports EXE/DLL download-and-execute, arbitrary command execution, registry Run-key persistence, and self-termination, and the actors were observed using RDP for lateral movement. In some cases the PHP variant subsequently deployed the original Node.js Interlock RAT.
Targeting appears opportunistic across a broad range of industries rather than sector-specific, reflecting continued tooling evolution by the Interlock group to improve resilience and evade detection. Researchers continue to monitor the cluster and plan further reporting.
Mentioned in this report
Source reporting: https://thedfirreport.com/2025/07/14/kongtuke-filefix-leads-to-new-interlock-rat-variant
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free