logo

How Interlock Ransomware Gang’s New RAT Slips Through the Cracks

ID: 4b0720d1-6394-58e1-b16e-b43e4d4b586a

STIX ID: report--4b0720d1-6394-58e1-b16e-b43e4d4b586a

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2025-07-15

Date Updated: 2026-04-28

...
...

Interlock (NodeSnake) is deploying a new PHP-based variant of the Interlock RAT via a "FileFix" attack chain that tricks users with fake CAPTCHAs into pasting a Windows Run command; the RAT collects detailed system data, persists through a hidden Registry script, uses Cloudflare Tunnel (with fallback IPs) for C2, and enables remote execution, payload deployment, and lateral movement — a high-sophistication ransomware playbook that relies on social engineering to bypass traditional EDR controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.