logo

KongTuke FileFix Leads to New Interlock RAT Variant

ID: 1f90300c-d6b7-5cff-a74b-a6e5e4123a84

STIX ID: report--1f90300c-d6b7-5cff-a74b-a6e5e4123a84

Feed Name: The DFIR Report

Threat Score
75/100

Date Published: 2025-07-14

Date Updated: 2026-04-19

Author: editor

...
...

Researchers report a new PHP-based variant of the Interlock RAT used by the Interlock ransomware group in a widespread web-inject campaign (KongTuke/LandUpdate808) since May–June 2025; the malware is delivered via single-line injected scripts that prompt victims into executing PowerShell chains, establishes resilient C2 using trycloudflare.com tunnels and fallback IPs, performs extensive system reconnaissance and discovery, achieves persistence via Run keys, and facilitates lateral movement (RDP), with IOCs including domains, IPs, and config file hashes provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.