# Interlock ransomware debuts PHP RAT via FileFix

Published: 2025-07-14 · Severity: high
Canonical: https://vorant.io/reports/d7ede32c-a315-5bd5-be83-3069e684a732/interlock-ransomware-debuts-php-rat-via-filefix

> Interlock ransomware group is using a new PHP-based RAT delivered through KongTuke/LandUpdate808 fake-CAPTCHA web injects and Cloudflare Tunnels for C2.

The DFIR Report, working with Proofpoint, identified a new PHP variant of the Interlock ransomware group's RAT, a departure from the group's earlier Node.js-based Interlock RAT (NodeSnake). The infection chain begins with compromised legitimate websites injected with a hidden single-line script tied to the LandUpdate808/KongTuke web-inject cluster. Victims are lured through a fake "Verify you are human" CAPTCHA and 'FileFix' verification steps that trick them into pasting and executing a malicious PowerShell command via the Windows Run dialog, which retrieves and launches PHP configured to load the RAT payload.

Once executed, the PHP-based Interlock RAT performs extensive automated discovery (system info, running processes/services, mounted drives, ARP neighbors, privilege level) and exfiltrates results as JSON, followed by hands-on-keyboard Active Directory and domain reconnaissance suggesting an interactive operator session. The malware establishes C2 over Cloudflare Tunnel (trycloudflare.com) subdomains with hardcoded fallback IPs for resilience, supports EXE/DLL download-and-execute, arbitrary command execution, registry Run-key persistence, and self-termination, and the actors were observed using RDP for lateral movement. In some cases the PHP variant subsequently deployed the original Node.js Interlock RAT.

Targeting appears opportunistic across a broad range of industries rather than sector-specific, reflecting continued tooling evolution by the Interlock group to improve resilience and evade detection. Researchers continue to monitor the cluster and plan further reporting.

## Mentioned in this report

- Threat actors: interlock
- Malware: Interlock RAT (Node.js/NodeSnake), Interlock RAT (PHP variant)
- Campaigns: KongTuke, LandUpdate808

Source reporting: https://thedfirreport.com/2025/07/14/kongtuke-filefix-leads-to-new-interlock-rat-variant

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d7ede32c-a315-5bd5-be83-3069e684a732/interlock-ransomware-debuts-php-rat-via-filefix.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
