KongTuke FileFix Leads to New Interlock RAT Variant
July 15, 2025, 9:46 a.m.
Description
A new and resilient variant of the Interlock ransomware group's remote access trojan (RAT) has been identified. This PHP-based malware, a shift from the previous JavaScript-based NodeSnake, is being used in a widespread campaign associated with the LandUpdate808 (KongTuke) web-inject threat clusters. The campaign begins with compromised websites injected with a hidden script, employing IP filtering to serve the payload. The malware performs automated reconnaissance, establishes command and control through Cloudflare Tunnels, and has various execution capabilities. It uses PowerShell for system profiling and discovery, creates persistence through registry modifications, and leverages RDP for lateral movement. The campaign appears to be opportunistic, targeting multiple industries.
Tags
Date
- Created: July 15, 2025, 8:57 a.m.
- Published: July 15, 2025, 8:57 a.m.
- Modified: July 15, 2025, 9:46 a.m.
Indicators
- 8afd6c0636c5d70ac0622396268786190a428635e9cf28ab23add939377727b0
- 28a9982cf2b4fc53a1545b6ed0d0c1788ca9369a847750f5652ffa0ca7f7b7d3
- 64.95.12.71
- 184.95.51.165
- http://deadly-programming-attorneys-our.trycloudflare.com
- ranked-accordingly-ab-hired.trycloudflare.com
- nowhere-locked-manor-hs.trycloudflare.com
- galleries-physicians-psp-wv.trycloudflare.com
- ferrari-rolling-facilities-lounge.trycloudflare.com
- existed-bunch-balance-councils.trycloudflare.com
- evidence-deleted-procedure-bringing.trycloudflare.com
- deadly-programming-attorneys-our.trycloudflare.com