← Threat Actors & APT Groups

Interlock

Every article that identifies Interlock as responsible for or connected to reported activity.

MalwareThe DFIR Report·1 year ago

KongTuke FileFix Leads to New Interlock RAT Variant

The Interlock ransomware group has deployed a new PHP-based variant of their remote access trojan, marking a significant shift from their previous JavaScript implementation known as NodeSnake. Researchers from The DFIR Report and Proofpoint have observed this evolved RAT being distributed through a campaign leveraging KongTuke FileFix, with notable activity detected since May 2025. This variant demonstrates increased resilience and represents an escalation in the group's technical capabilities.