KongTuke FileFix Leads to New Interlock RAT Variant
ID: 1f90300c-d6b7-5cff-a74b-a6e5e4123a84
STIX ID: report--1f90300c-d6b7-5cff-a74b-a6e5e4123a84
Feed Name: The DFIR Report
Researchers report a new PHP-based variant of the Interlock RAT used by the Interlock ransomware group in a widespread web-inject campaign (KongTuke/LandUpdate808) since May–June 2025; the malware is delivered via single-line injected scripts that prompt victims into executing PowerShell chains, establishes resilient C2 using trycloudflare.com tunnels and fallback IPs, performs extensive system reconnaissance and discovery, achieves persistence via Run keys, and facilitates lateral movement (RDP), with IOCs including domains, IPs, and config file hashes provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
