KongTuke FileFix Campaign Delivers a New PHP-Based Interlock RAT

Summary
Researchers report that KongTuke web injections and a FileFix delivery method are deploying a new PHP-based Interlock RAT, which profiles compromised Windows systems, communicates through Cloudflare Tunnels and fallback IPs, and can enable persistence and remote command
Key points
- Researchers observed a PHP-based variant of the Interlock RAT, first seen in June 2025 campaigns, alongside the previously known Node.js variant.
- Compromised websites use injected JavaScript and a fake CAPTCHA workflow to trick visitors into pasting commands into Windows Run, leading to PowerShell execution and RAT deployment.
- The malware profiles Windows systems, processes, services, drives, network neighbors, privilege level, and Active Directory resources.
- Its command-and-control traffic uses trycloudflare.com tunnels and hardcoded fallback IP addresses.
- The RAT can download and run EXE or DLL files, execute attacker-supplied commands, and establish persistence through a Windows Registry Run key.
- Researchers observed RDP for lateral movement and describe the campaign as opportunistic across a broad range of industries.
Article Details
- Attack Vectors
- Compromised websites carried a hidden, single-line HTML script linked to the LandUpdate808 (aka KongTuke) web-inject activity.
- The delivery flow prompted visitors to complete a CAPTCHA, then follow instructions to paste clipboard content into the Windows Run dialog. The pasted command executed PowerShell and led to Interlock RAT.
- Researchers observed the KongTuke web-inject transition to a FileFix variant that delivered the PHP variant of Interlock RAT; in some cases, that variant subsequently deployed the Node.js variant.
- RDP was used to move through victim environments.
- Defensive Notes
- The report identifies PowerShell launching PHP from a user's AppData\Roaming directory with a non-standard configuration-file input as suspicious execution behavior.
- The reported RAT persistence used an HKCU Windows Registry Run-key entry pointing to the PHP executable and configuration file.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| HOSTNAME | evidence-deleted-procedure-bringing[.]trycloudflare[.]com | Listed Interlock RAT PHP variant C2 hostname. |
| HOSTNAME | existed-bunch-balance-councils[.]trycloudflare[.]com | Listed Interlock RAT PHP variant C2 hostname. |
| HOSTNAME | ferrari-rolling-facilities-lounge[.]trycloudflare[.]com | Listed Interlock RAT PHP variant C2 hostname. |
| HOSTNAME | galleries-physicians-psp-wv[.]trycloudflare[.]com | Listed Interlock RAT PHP variant C2 hostname. |
| HOSTNAME | nowhere-locked-manor-hs[.]trycloudflare[.]com | Listed Interlock RAT PHP variant C2 hostname. |
| HOSTNAME | ranked-accordingly-ab-hired[.]trycloudflare[.]com | Listed Interlock RAT PHP variant C2 hostname. |
| IPV4 | 184[.]95[.]51[.]165 | Listed fallback IP address for the Interlock RAT PHP variant's C2 communications. |
| IPV4 | 64[.]95[.]12[.]71 | Listed fallback IP address for the Interlock RAT PHP variant's C2 communications. |
| SHA256 | 28a9982cf2b4fc53a1545b6ed0d0c1788ca9369a847750f5652ffa0ca7f7b7d3 | SHA-256 of a config.cfg file listed in the report's Interlock RAT IOCs. |
| SHA256 | 8afd6c0636c5d70ac0622396268786190a428635e9cf28ab23add939377727b0 | SHA-256 of a second config.cfg file listed in the report's Interlock RAT IOCs. |
| URL | hxxp[:]//deadly-programming-attorneys-our[.]trycloudflare[.]com | URL in the observed PowerShell command that downloaded and executed content leading to Interlock RAT. |
MITRE ATT&CK
T1007 · System Service DiscoveryThe RAT used Get-Service to enumerate Windows services.T1016 · System Network Configuration DiscoveryThe RAT used Get-NetNeighbor to collect local network-neighbor information.T1018 · Remote System DiscoveryObserved commands searched Active Directory for computers and used nltest to list domain controllers.T1021.001 · Remote Desktop ProtocolThe report states that RDP was used to move through victim environments.T1033 · System Owner/User DiscoveryThe RAT checked whether it was running as USER, ADMIN, or SYSTEM; an observed interactive command also ran whoami.T1041 · Exfiltration Over C2 ChannelThe RAT gathered a system profile as JSON data and exfiltrated it through its command-and-control channel.T1057 · Process DiscoveryThe RAT ran tasklist to enumerate running processes, including associated services.T1059.001 · PowerShellThe initial command used PowerShell to download and execute content, and the RAT later ran PowerShell discovery commands.T1059.003 · Windows Command ShellThe PHP-based RAT invoked cmd.exe to run discovery commands and could execute shell commands received from its operator.T1082 · System Information DiscoveryThe RAT ran systeminfo and converted the results to JSON as part of its system profile.T1083 · File and Directory DiscoveryThe RAT enumerated mounted file-system drives with Get-PSDrive, and an observed command listed the AppData directory.T1087.002 · Domain AccountObserved commands queried domain user information with net user /domain and searched Active Directory user objects.T1105 · Ingress Tool TransferThe initial PowerShell command downloaded executable content; the RAT could also download EXE and DLL files on operator command.T1204.004 · Malicious Copy and PasteThe delivery flow instructed visitors to paste clipboard content into the Windows Run dialog, executing a PowerShell command that led to Interlock RAT.T1218.011 · Rundll32The RAT's DLL command downloaded a DLL and executed it with rundll32.exe.T1547.001 · Registry Run Keys / Startup FolderThe RAT created an HKCU Windows Registry Run-key entry to launch its PHP executable and configuration file.
Threat Actors
Malware
Interlock RATThis new malware, a shift from the previously identified JavaScript-based Interlock RAT (aka NodeSnake), uses PHP and is being used in a widespread campaign.NodeSnakeThis new malware, a shift from the previously identified JavaScript-based Interlock RAT (aka NodeSnake), uses PHP and is being used in a widespread campaign.
Vendors
Products
Cloudflare TunnelNotably, it leverages trycloudflare.com URLs, abusing the legitimate Cloudflare Tunnel service to mask the true location of the C2 server.Microsoft Windowsspecifications (systeminfo), a list of all running processes and associated services (tasklist), running Windows services (Get-Service), all mounted drives (Get-PSDrive), and the local network neighborhood via the ARPNode.jsProofpoint researchers have observed both Interlock RAT Node.js and Interlock RAT PHP based variants.PHPThis new malware, a shift from the previously identified JavaScript-based Interlock RAT (aka NodeSnake), uses PHP and is being used in a widespread campaign.PowerShellIf pasted into the run command it will execute a PowerShell script which eventually leads to Interlock RAT.