KongTuke FileFix Campaign Delivers a New PHP-Based Interlock RAT

· Original article ↗

Summary

Researchers report that KongTuke web injections and a FileFix delivery method are deploying a new PHP-based Interlock RAT, which profiles compromised Windows systems, communicates through Cloudflare Tunnels and fallback IPs, and can enable persistence and remote command

Key points

  • Researchers observed a PHP-based variant of the Interlock RAT, first seen in June 2025 campaigns, alongside the previously known Node.js variant.
  • Compromised websites use injected JavaScript and a fake CAPTCHA workflow to trick visitors into pasting commands into Windows Run, leading to PowerShell execution and RAT deployment.
  • The malware profiles Windows systems, processes, services, drives, network neighbors, privilege level, and Active Directory resources.
  • Its command-and-control traffic uses trycloudflare.com tunnels and hardcoded fallback IP addresses.
  • The RAT can download and run EXE or DLL files, execute attacker-supplied commands, and establish persistence through a Windows Registry Run key.
  • Researchers observed RDP for lateral movement and describe the campaign as opportunistic across a broad range of industries.

Article Details

Attack Vectors
  • Compromised websites carried a hidden, single-line HTML script linked to the LandUpdate808 (aka KongTuke) web-inject activity.
  • The delivery flow prompted visitors to complete a CAPTCHA, then follow instructions to paste clipboard content into the Windows Run dialog. The pasted command executed PowerShell and led to Interlock RAT.
  • Researchers observed the KongTuke web-inject transition to a FileFix variant that delivered the PHP variant of Interlock RAT; in some cases, that variant subsequently deployed the Node.js variant.
  • RDP was used to move through victim environments.
Defensive Notes
  • The report identifies PowerShell launching PHP from a user's AppData\Roaming directory with a non-standard configuration-file input as suspicious execution behavior.
  • The reported RAT persistence used an HKCU Windows Registry Run-key entry pointing to the PHP executable and configuration file.

Indicators of compromise

TypeIndicatorContext
HOSTNAMEevidence-deleted-procedure-bringing[.]trycloudflare[.]comListed Interlock RAT PHP variant C2 hostname.
HOSTNAMEexisted-bunch-balance-councils[.]trycloudflare[.]comListed Interlock RAT PHP variant C2 hostname.
HOSTNAMEferrari-rolling-facilities-lounge[.]trycloudflare[.]comListed Interlock RAT PHP variant C2 hostname.
HOSTNAMEgalleries-physicians-psp-wv[.]trycloudflare[.]comListed Interlock RAT PHP variant C2 hostname.
HOSTNAMEnowhere-locked-manor-hs[.]trycloudflare[.]comListed Interlock RAT PHP variant C2 hostname.
HOSTNAMEranked-accordingly-ab-hired[.]trycloudflare[.]comListed Interlock RAT PHP variant C2 hostname.
IPV4184[.]95[.]51[.]165Listed fallback IP address for the Interlock RAT PHP variant's C2 communications.
IPV464[.]95[.]12[.]71Listed fallback IP address for the Interlock RAT PHP variant's C2 communications.
SHA25628a9982cf2b4fc53a1545b6ed0d0c1788ca9369a847750f5652ffa0ca7f7b7d3SHA-256 of a config.cfg file listed in the report's Interlock RAT IOCs.
SHA2568afd6c0636c5d70ac0622396268786190a428635e9cf28ab23add939377727b0SHA-256 of a second config.cfg file listed in the report's Interlock RAT IOCs.
URLhxxp[:]//deadly-programming-attorneys-our[.]trycloudflare[.]comURL in the observed PowerShell command that downloaded and executed content leading to Interlock RAT.

MITRE ATT&CK

T1007 · System Service DiscoveryThe RAT used Get-Service to enumerate Windows services.T1016 · System Network Configuration DiscoveryThe RAT used Get-NetNeighbor to collect local network-neighbor information.T1018 · Remote System DiscoveryObserved commands searched Active Directory for computers and used nltest to list domain controllers.T1021.001 · Remote Desktop ProtocolThe report states that RDP was used to move through victim environments.T1033 · System Owner/User DiscoveryThe RAT checked whether it was running as USER, ADMIN, or SYSTEM; an observed interactive command also ran whoami.T1041 · Exfiltration Over C2 ChannelThe RAT gathered a system profile as JSON data and exfiltrated it through its command-and-control channel.T1057 · Process DiscoveryThe RAT ran tasklist to enumerate running processes, including associated services.T1059.001 · PowerShellThe initial command used PowerShell to download and execute content, and the RAT later ran PowerShell discovery commands.T1059.003 · Windows Command ShellThe PHP-based RAT invoked cmd.exe to run discovery commands and could execute shell commands received from its operator.T1082 · System Information DiscoveryThe RAT ran systeminfo and converted the results to JSON as part of its system profile.T1083 · File and Directory DiscoveryThe RAT enumerated mounted file-system drives with Get-PSDrive, and an observed command listed the AppData directory.T1087.002 · Domain AccountObserved commands queried domain user information with net user /domain and searched Active Directory user objects.T1105 · Ingress Tool TransferThe initial PowerShell command downloaded executable content; the RAT could also download EXE and DLL files on operator command.T1204.004 · Malicious Copy and PasteThe delivery flow instructed visitors to paste clipboard content into the Windows Run dialog, executing a PowerShell command that led to Interlock RAT.T1218.011 · Rundll32The RAT's DLL command downloaded a DLL and executed it with rundll32.exe.T1547.001 · Registry Run Keys / Startup FolderThe RAT created an HKCU Windows Registry Run-key entry to launch its PHP executable and configuration file.

Threat Actors

Malware

Vendors

Products

Related Articles