Analysis of KongTuke FileFix Leads to New Interlock RAT Variant
Executive summary
Technical threat analysis derived from intelligence published at https://thedfirreport.com/2025/07/14/kongtuke-filefix-leads-to-new-interlock-rat-variant/. KongTuke FileFix Leads to New Interlock RAT Variant Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT). This new malware, a shift from the previously identified JavaScript-based Interlock RAT (aka NodeSnake), uses PHP and is being used in a widespread campaign. Since May 2025, activity related to […] The post KongTuke FileFix Leads to New Interlock RAT Variant appeared first on The DFIR Report.
Technical analysis
Technical threat analysis derived from intelligence published at https://thedfirreport.com/2025/07/14/kongtuke-filefix-leads-to-new-interlock-rat-variant/. KongTuke FileFix Leads to New Interlock RAT Variant Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT). This new malware, a shift from the previously identified JavaScript-based Interlock RAT (aka NodeSnake), uses PHP and is being used in a widespread campaign. Since May 2025, activity related to […] The post KongTuke FileFix Leads to New Interlock RAT Variant appeared first on The DFIR Report.
Evidence and sources
Analysis of KongTuke FileFix Leads to New Interlock RAT Variant. Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT). This new malware, a shift from the previously identified JavaScript-based Interlock RAT (aka NodeSnake), uses PHP and is being used in a widespread campaign. Since May 2025, activity related to […] The post KongTuke FileFix Leads to New Interlock RAT Variant appeared first on The DFIR Report.. KongTuke FileFix Leads to New Interlock RAT Variant Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT). This new malware, a shift from the previously identified JavaScript-based Interlock RAT (aka NodeSnake), uses PHP and is being used in a widespread campaign. Since May 2025, activity related to […] The post KongTuke FileFix Leads to New Interlock RAT Variant appeared first on The DFIR Report.
Analysis of KongTuke FileFix Leads to New Interlock RAT Variant. Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT). This new malware, a shift from the previously identified JavaScript-based Interlock RAT (aka NodeSnake), uses PHP and is being used in a widespread campaign. Since May 2025, activity related to […] The post KongTuke FileFix Leads to New Interlock RAT Variant appeared first on The DFIR Report.. KongTuke FileFix Leads to New Interlock RAT Variant Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT). This new malware, a shift from the previously identified JavaScript-based Interlock RAT (aka NodeSnake), uses PHP and is being used in a widespread campaign. Since May 2025, activity related to […] The post KongTuke FileFix Leads to New Interlock RAT Variant appeared first on The DFIR Report.
IOCs
No public IOC is available.
CVEs and affected products
No CVE or affected product is available.
ATT&CK mapping
No ATT&CK mapping is available.
Detection content
Sigma rules, YARA rules, Splunk SPL, and KQL detection logic.
Threat hunting
Hypothesis-driven hunt procedures and telemetry checklist.
Remediation
Containment actions, patching notes, and credential steps.
Historical relationships
No published historical relationship is available.
Timeline and change history
Confidence and caveats
0.95
⚠️ This report describes public threat intelligence only and makes no assertion regarding internal organizational exposure.