New PHP-Based Interlock RAT Variant Uses FileFix Delivery Mechanism to Target Multiple Industries
As part of an extensive campaign utilizing a ClickFix variant known as FileFix, threat actors behind the Interlock ransomware gang have released a new PHP variant of their custom remote access trojan (RAT).
In a technical investigation released today in partnership with Proofpoint, The DFIR Report stated that since May 2025, Interlock RAT activity has been noted in relation to the LandUpdate808 (also known as KongTuke) web-inject threat clusters.
The campaign starts with hijacked websites that, frequently without the owners' or visitors' knowledge, have a single-line script inserted into the HTML of the page.
Using IP filtering techniques, the JavaScript code functions as a traffic distribution system (TDS), directing users to phony CAPTCHA verification pages that employ ClickFix...

