Interlock RAT Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
January 21, 2026
Last Seen
January 21, 2026

Interlock RAT is a Python-based remote access trojan family that is being distributed through a malicious ad blocker extension.

Overview

Interlock RAT is a Python-based remote access trojan family that is being distributed through a malicious ad blocker extension. The campaign uses a component or loader named CrashFix to deliver the RAT payload, illustrating how browser extension ecosystems can be abused to deploy backdoors. This is significant as it showcases Python-based malware delivered via trusted-looking extensions, increasing stealth and reach on Windows hosts.

Related Threat Clusters

Recent Intelligence Reports

  • Malicious ad blocker extension uses 'CrashFix' to spread new Python RAT — Scmagazine · January 21, 2026

CVSS v3.1 Breakdown