Listen to this Post

A Silent Infiltration Begins
Cybercriminals linked to the Interlock ransomware group have escalated their operations with a dangerous new twist — a PHP-based version of their infamous Interlock Remote Access Trojan (RAT). This latest variant, uncovered in a major campaign utilizing a refined tool dubbed FileFix, marks a new level of sophistication in the group’s strategy to infiltrate systems across industries globally. The attack chain begins quietly — a single-line JavaScript injection on legitimate websites — but ends in deep system compromise, persistent surveillance, and remote command execution. What makes this especially alarming is the shift from Node.js to PHP, signaling broader targeting capabilities and stealthier persistence methods.
Inside the Attack: the Threat Landscape
Since May 2025, cybersecurity researchers have detected heightened activity involving the Interlock RAT, particularly tied to the LandUpdate808 (aka KongTuke) threat clusters. These operations kick off with compromised websites harboring hidden JavaScript lines in their HTML — lines site owners typically don’t notice. This malicious code functions as a Traffic Distribution System (TDS), redirecting unsuspecting visitors through IP-based filters to counterfeit CAPTCHA verification pages.
These decoy pages activate ClickFix — or more precisely, its newer iteration, FileFix — tricking users into running a PowerShell script. That script silently deploys Interlock RAT, also known as NodeSnake, due to its Node.js coding origins. Previously seen targeting UK local governments and universities earlier in 2025, the malware allows persistent infiltration, system scanning, and command execution by threat actors.
The shift now? A newly observed PHP variant of Interlock is spreading via FileFix, enabling attacks on a broader range of targets. Researchers say the campaign appears opportunistic, not industry-specific. Interestingly, some attacks begin with the PHP variant and later evolve into full Node.js-based deployment.
FileFix, an evolution of ClickFix, uses a clever social engineering trick — victims are instructed to paste malicious commands into their Windows File Explorer address bar, often mistaking them for legitimate tasks. Once installed, the RAT conducts host reconnaissance, checks privilege levels (USER, ADMIN, SYSTEM), and communicates with command servers to download additional payloads in .EXE or .DLL format.
Persistence is achieved by modifying Windows Registry settings, while lateral movement within networks is enabled via Remote Desktop Protocol (RDP). To hide its command-and-control infrastructure, the malware abuses Cloudflare Tunnel subdomains and hardcodes IP addresses as a backup, ensuring continuous contact even if tunnels are disabled.
This change in tactics — switching from Node.js to PHP — reflects a growing adaptability and technical depth within the Interlock group. PHP, being a ubiquitous web scripting language, may offer new avenues of access in environments where Node.js might raise suspicion or be less common.
🔍 What Undercode Say:
The Rise of FileFix: Social Engineering in Action
One of the most concerning aspects of this campaign is the delivery method. FileFix demonstrates a high level of user manipulation, bypassing traditional phishing by exploiting trust in everyday UI elements. Victims are not just clicking links — they’re actively pasting commands into their systems, giving attackers unfiltered access.
PHP: A Strategic Shift for Wider Reach
The move to a PHP variant is not random. PHP is nearly everywhere — from WordPress sites to internal web tools. This gives Interlock a massive attack surface. Using PHP, they can hide their RAT within familiar environments, evading detection tools fine-tuned for Node.js-based threats.
Multi-Stage Attacks: From PHP to Node.js
In some cases, the PHP version is only the entry point. Once foothold is gained, a Node.js variant is deployed for deeper control. This staged approach gives Interlock flexibility: lightweight initial payloads, followed by more robust control mechanisms if needed.
Cloudflare Tunnel Obfuscation: Defying Detection
The abuse of Cloudflare Tunnel subdomains is especially clever. It disguises malicious command centers behind legitimate services. Even if cybersecurity teams identify and block one access point, the malware has fallback IP addresses hardcoded for resilience. This redundancy significantly complicates incident response.
Target Scope: No One Is Safe
The opportunistic nature of these campaigns makes them dangerous for everyone — not just high-profile targets. From small businesses to educational institutions, any organization running a vulnerable web environment or misconfigured systems could become a victim.
Advanced Reconnaissance and Privilege Detection
Once inside, Interlock RAT evaluates the infected system’s privilege level, adjusts its behavior accordingly, and conducts thorough reconnaissance. This ensures the attackers maximize access and minimize detection. It’s more than malware — it’s an intelligent infiltration framework.
✅ Fact Checker Results:
✅ Confirmed by The DFIR Report and Proofpoint.
✅ PHP variant deployment verified in recent campaigns.
✅ FileFix attack vector validated through behavioral analysis.
🔮 Prediction: What’s Coming Next?
Expect more campaigns leveraging familiar scripting environments like PHP, Python, and even browser-based automation tools. The Interlock group’s adaptability means future variants may integrate machine learning for automated privilege escalation or sandbox evasion. Also, with FileFix proving effective, look out for similar address-bar-driven exploits repackaged for different operating systems — especially macOS and Linux. Cloudflare Tunnels and similar obfuscation tools will become more common as attackers try to stay ahead of threat detection technologies. This campaign is just a preview of more covert, widespread, and technically diverse attacks to come.
References:
Reported By: thehackernews.com
Extra Source Hub:
https://www.reddit.com/r/AskReddit
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




