New Variant of Interlock Ransomware Revealed
The cybersecurity landscape is becoming increasingly troubling as new tactics emerge from threat actors. The Interlock ransomware group has recently introduced a PHP variant of its unique remote access trojan (RAT), marking a significant development in its ongoing campaign. This update, identified as a part of a broader operation involving a modified ClickFix tool called FileFix, raises concerns about the potential for widespread exploitation.
Observations from Recent Security Reports
According to a detailed analysis by DFIR Report, in collaboration with Proofpoint, activity linked to the Interlock RAT has intensified since May 2025. This latest wave correlates with the LandUpdate808 (also referred to as KongTuke), a series of web-injection threat clusters. The method of attack typically involves compromised websites that subtly incorporate a single-line script into their HTML code. Alarmingly, these modifications often go unnoticed not just by visitors, but also by the website owners themselves.
How the Attack Unfolds
The newly introduced JavaScript code operates as a traffic distribution system (TDS). It employs IP filtering techniques designed to reroute unsuspecting users to counterfeit CAPTCHA verification pages. These pages entice users into executing a PowerShell script that ultimately leads to the deployment of the NodeSnake variant of the Interlock RAT. This tactic not only demonstrates the creativity of the attackers but also underscores the dangers of seemingly innocuous website interactions.
Historical Context and Targets
Interlock’s NodeSnake malware is not entirely new to the cybersecurity realm. Past reports from Quorum Cyber have linked it to cyber attacks targeting local governments and higher education institutions in the United Kingdom as early as January and March 2025. The RAT is engineered to allow persistent access, enabling thorough system reconnaissance and remote command execution, thus heightening its malicious effectiveness.
Transitioning to PHP
Interestingly, recent campaigns have included the distribution of a PHP variant through the FileFix mechanism. This shift appears opportunistic, as it targets various industries, demonstrating the group’s adaptability in exploiting vulnerabilities across different sectors. Researchers noted that this enhanced delivery method can deploy the PHP variant alongside the Node.js variant, increasing the malware’s reach.
Innovations in Delivery Mechanisms
FileFix represents an evolution from the original ClickFix, capitalizing on the functionality of the Windows operating system. Victims are misled into executing commands via the File Explorer’s address bar feature. This mechanism was first presented as a proof-of-concept by security researcher mrd0x.
Once successfully installed, the RAT undertakes a series of reconnaissance activities on the host system and exfiltrates information formatted in JSON. It checks its own operational privileges, assessing whether it is running as USER, ADMIN, or SYSTEM. Subsequently, it establishes communication with a remote server, allowing it to download and execute EXE or DLL files.
Ensuring Persistence and Evasion
The Interlock RAT secures its persistence through modifications to the Windows Registry, while the Remote Desktop Protocol (RDP) facilitates lateral movement across networks. One particularly noteworthy feature is its utilization of Cloudflare Tunnel subdomains. This tactic effectively conceals the true location of the command-and-control (C2) server. Moreover, the malware contains hard-coded IP addresses as a backup to maintain communication, even if the Cloudflare Tunnel is compromised.
Implications of Evolving Cyber Threats
The researchers behind this analysis highlight the increasing sophistication of the Interlock group’s operational capabilities. Although the Node.js variant is well-documented, the emergence of a PHP version showcases a strategic shift that utilizes a common web scripting language for infiltrating and maintaining access to victim networks.
In summary, the ongoing advancements in malware tactics, like those seen with the Interlock ransomware group, underscore the necessity for proactive security measures and awareness in both individual and organizational contexts.


