Interlock Ransomware Deploys New PHP RAT via FileFix Phishing

Red | Attack Report
Download PDF

Interlock ransomware has introduced a new PHP-based RAT delivered via the FileFix attack method, tricking users into executing malicious PowerShell commands through fake CAPTCHA prompts. This campaign uses compromised legitimate websites and Cloudflare Tunnel for stealthy C2 communication. The RAT conducts deep system reconnaissance and enables hands-on intrusion activities. It marks a significant escalation in Interlock’s tactics, combining advanced social engineering with persistent malware operations.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox

Cyber Horizons 2025

What Last Year’s Attacks Reveal About Today’s Risks

Watch the Webinar on-demand and get a FREE copy of our Cyber Horizons 2025 report.

Our Speakers
Speaker 1

Prateek Bhajanka Global Field CISO & Former Gartner Analyst Hive Pro Inc.

Speaker 2

Ankit Mani Manager Threat Intel HiveForce Labs

Speaker 3

Sreevani Tonipe Senior Threat Researcher HiveForce Labs