New PHP Interlock RAT Variant Targets Multiple Industries via FileFix Delivery Mechanism

Published:

spot_img

New Variant of Interlock Ransomware Revealed

The cybersecurity landscape is becoming increasingly troubling as new tactics emerge from threat actors. The Interlock ransomware group has recently introduced a PHP variant of its unique remote access trojan (RAT), marking a significant development in its ongoing campaign. This update, identified as a part of a broader operation involving a modified ClickFix tool called FileFix, raises concerns about the potential for widespread exploitation.

Observations from Recent Security Reports

According to a detailed analysis by DFIR Report, in collaboration with Proofpoint, activity linked to the Interlock RAT has intensified since May 2025. This latest wave correlates with the LandUpdate808 (also referred to as KongTuke), a series of web-injection threat clusters. The method of attack typically involves compromised websites that subtly incorporate a single-line script into their HTML code. Alarmingly, these modifications often go unnoticed not just by visitors, but also by the website owners themselves.

How the Attack Unfolds

The newly introduced JavaScript code operates as a traffic distribution system (TDS). It employs IP filtering techniques designed to reroute unsuspecting users to counterfeit CAPTCHA verification pages. These pages entice users into executing a PowerShell script that ultimately leads to the deployment of the NodeSnake variant of the Interlock RAT. This tactic not only demonstrates the creativity of the attackers but also underscores the dangers of seemingly innocuous website interactions.

Historical Context and Targets

Interlock’s NodeSnake malware is not entirely new to the cybersecurity realm. Past reports from Quorum Cyber have linked it to cyber attacks targeting local governments and higher education institutions in the United Kingdom as early as January and March 2025. The RAT is engineered to allow persistent access, enabling thorough system reconnaissance and remote command execution, thus heightening its malicious effectiveness.

Transitioning to PHP

Interestingly, recent campaigns have included the distribution of a PHP variant through the FileFix mechanism. This shift appears opportunistic, as it targets various industries, demonstrating the group’s adaptability in exploiting vulnerabilities across different sectors. Researchers noted that this enhanced delivery method can deploy the PHP variant alongside the Node.js variant, increasing the malware’s reach.

Innovations in Delivery Mechanisms

FileFix represents an evolution from the original ClickFix, capitalizing on the functionality of the Windows operating system. Victims are misled into executing commands via the File Explorer’s address bar feature. This mechanism was first presented as a proof-of-concept by security researcher mrd0x.

Once successfully installed, the RAT undertakes a series of reconnaissance activities on the host system and exfiltrates information formatted in JSON. It checks its own operational privileges, assessing whether it is running as USER, ADMIN, or SYSTEM. Subsequently, it establishes communication with a remote server, allowing it to download and execute EXE or DLL files.

Ensuring Persistence and Evasion

The Interlock RAT secures its persistence through modifications to the Windows Registry, while the Remote Desktop Protocol (RDP) facilitates lateral movement across networks. One particularly noteworthy feature is its utilization of Cloudflare Tunnel subdomains. This tactic effectively conceals the true location of the command-and-control (C2) server. Moreover, the malware contains hard-coded IP addresses as a backup to maintain communication, even if the Cloudflare Tunnel is compromised.

Implications of Evolving Cyber Threats

The researchers behind this analysis highlight the increasing sophistication of the Interlock group’s operational capabilities. Although the Node.js variant is well-documented, the emergence of a PHP version showcases a strategic shift that utilizes a common web scripting language for infiltrating and maintaining access to victim networks.

In summary, the ongoing advancements in malware tactics, like those seen with the Interlock ransomware group, underscore the necessity for proactive security measures and awareness in both individual and organizational contexts.

spot_img

Related articles

Recent articles

Origin Energy Data Breach 2026: Unauthorized Access Exposes PII of 900,000 Customers

On July 28, 2026, Origin Energy confirmed a significant data breach impacting approximately 900,000 current and former customers. This incident involved unauthorized access and...

Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is...

Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Bank of Baroda, one of India's largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and...

Fairlife resumes US production after ransomware attack, data breach confirmed

USA – The Coca-Cola Company has announced that its dairy subsidiary Fairlife has resumed most production across its four US facilities following a ransomware...