← Back to Feed
KongTuke FileFix Leads to New Interlock RAT Variant
July 14, 2025 · DFIR Report · Severity: CRITICAL
Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT). This new malware, a shift from the previously identified JavaScript-based Interlock RAT (aka NodeSnake), uses PHP and is being used in a widespread campaign. Since May 2025, activity related to […] The post KongTuke FileFix Leads to New Interlock RAT Variant appeared first on The DFIR Report.
Key Takeaways
- DFIR Report details how KongTuke FileFix leads to a new Interlock RAT variant, providing technical analysis of the infection chain.
- The Interlock RAT variant uses fileless persistence techniques and encrypted C2 communications to evade detection by security tools.
- Organizations should review the full article for complete details and implement relevant security measures.