#InterlockRAT
🚨 New Interlock RAT variant spotted!

Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT).

🔎 thedfirreport.com/2025/07/14/k...

#DFIR #KongTuke #InterlockRAT #FileFix
KongTuke FileFix Leads to New Interlock RAT Variant
Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT). This new malware,…
thedfirreport.com
July 14, 2025 at 11:36 AM
💥 Upgraded Interlock RAT via fake CAPTCHA & PowerShell in KongTuke FileFix.

☁️ Uses Cloudflare Tunnel to hide C2
📡 Hardcoded IPs keep it running if blocked
🧠 Steals system info, services, and more

Report:
shorturl.at/3nVzB

#InterlockRAT #KongTuke #Malware #Cybersecurity
July 15, 2025 at 6:56 AM
Hive0163 ransomware group deployed AI-generated Slopoly malware, a PowerShell-based C2 persistence client, alongside NodeSnake, InterlockRAT, and Interlock ransomware in a 2026 attack. #AIThreats #Ransomware #Slopoly
Hive0163 Ransomware Operators Use AI-Generated Slopoly Malware
Researchers identified a suspected case of AI-generated malware called Slopoly used by the financially motivated group Hive0163 during a 2026 ransomware intrusion. Slopoly acted as a PowerShell-based C2 persistence client deployed late in the attack chain alongside NodeSnake, InterlockRAT and Interlock ransomware, indicating threat actors are experimenting with LLM-assisted malware generation....
www.hendryadrian.com
March 13, 2026 at 11:20 AM
IBM X-Force found Hive0163 deploying AI-assisted PowerShell backdoor Slopoly for persistence in ransomware operations alongside NodeSnake, InterlockRAT and Windows Interlock (JunkFiction/JunkFiction loader). #Slopoly #Hive0163 #AIThreat https://bit.ly/4brk8VA
March 14, 2026 at 10:50 AM
Hive0163 used Slopoly as a C2 persistence client, deployed after initial access via ClickFix attacks. The chain included NodeSnake and InterlockRAT, enabling long-term access, data theft, and ransomware deployment across compromised systems.
March 17, 2026 at 8:43 AM