KongTuke Attacking Windows Users With New Interlock RAT Variant Using FileFix Technique

A sophisticated malware campaign leveraging the KongTuke threat cluster has emerged, targeting Windows users through a novel FileFix technique that deploys an advanced PHP-based variant of the Interlock remote access trojan (RAT). This represents a significant evolution from JavaScript-based implementations, demonstrating increased operational sophistication and resilience. Since May 2025, cybersecurity researchers have observed widespread activity related to the Interlock RAT in connection with...

Save to Folder

Choose a folder to save this article: