VORANT. Threat Intelligence Sign in Get the full feed

Interlock ransomware debuts PHP RAT via FileFix

high threat

Interlock ransomware group is using a new PHP-based RAT delivered through KongTuke/LandUpdate808 fake-CAPTCHA web injects and Cloudflare Tunnels for C2.

The DFIR Report, working with Proofpoint, identified a new PHP variant of the Interlock ransomware group's RAT, a departure from the group's earlier Node.js-based Interlock RAT (NodeSnake). The infection chain begins with compromised legitimate websites injected with a hidden single-line script tied to the LandUpdate808/KongTuke web-inject cluster. Victims are lured through a fake "Verify you are human" CAPTCHA and 'FileFix' verification steps that trick them into pasting and executing a malicious PowerShell command via the Windows Run dialog, which retrieves and launches PHP configured to load the RAT payload.

Once executed, the PHP-based Interlock RAT performs extensive automated discovery (system info, running processes/services, mounted drives, ARP neighbors, privilege level) and exfiltrates results as JSON, followed by hands-on-keyboard Active Directory and domain reconnaissance suggesting an interactive operator session. The malware establishes C2 over Cloudflare Tunnel (trycloudflare.com) subdomains with hardcoded fallback IPs for resilience, supports EXE/DLL download-and-execute, arbitrary command execution, registry Run-key persistence, and self-termination, and the actors were observed using RDP for lateral movement. In some cases the PHP variant subsequently deployed the original Node.js Interlock RAT.

Targeting appears opportunistic across a broad range of industries rather than sector-specific, reflecting continued tooling evolution by the Interlock group to improve resilience and evade detection. Researchers continue to monitor the cluster and plan further reporting.

Mentioned in this report

Threat actors interlock
Malware Interlock RAT (Node.js/NodeSnake)Interlock RAT (PHP variant)
Campaigns KongTukeLandUpdate808

Source reporting: https://thedfirreport.com/2025/07/14/kongtuke-filefix-leads-to-new-interlock-rat-variant

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free