How Interlock Ransomware Gang’s New RAT Slips Through the Cracks
ID: 4b0720d1-6394-58e1-b16e-b43e4d4b586a
STIX ID: report--4b0720d1-6394-58e1-b16e-b43e4d4b586a
Feed Name: Halcyon Blog
Interlock (NodeSnake) is deploying a new PHP-based variant of the Interlock RAT via a "FileFix" attack chain that tricks users with fake CAPTCHAs into pasting a Windows Run command; the RAT collects detailed system data, persists through a hidden Registry script, uses Cloudflare Tunnel (with fallback IPs) for C2, and enables remote execution, payload deployment, and lateral movement — a high-sophistication ransomware playbook that relies on social engineering to bypass traditional EDR controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
