Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Top mobile phones under Rs 15,000 in India (August 2025): Redmi Note 14 SE 5G, Tecno Pova 7, IQoo Z10X, and more

    August 5, 2025

    A top designer was banned from drill. Now he is creating his own contestant.

    August 4, 2025

    Anthropic AI wants to stop the model from evil – how is here

    August 4, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Interlock ransomware adopts filefix method for providing malware
    Security

    Interlock ransomware adopts filefix method for providing malware

    PineapplesUpdateBy PineapplesUpdateJuly 14, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Interlock ransomware adopts filefix method for providing malware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Interlock ransomware adopts filefix method for providing malware

    Hackers have adopted a new technology called ‘Filefix’ in the interlock ransomware attacks to release a remote access trojan (RAT) on targeted systems.

    The interlock ransomware operations have increased in the previous months as the danger actor has started using Kongtuk web injector (aka ‘Land update 808’) to distribute payload through compromise websites.

    This change in Modus operandi was seen from May from May by researchers on DFIR reports and proofpoints. Subsequently, visitors of the compromised sites were motivated to pass a fake captcha + verification, and then pasted into a run dialogue material, which was automatically saved on the clipboard, a strategy to suit the clickfix attacks.

    Tricks inspired users to execute a powerrashel script, bringing and launching a node.JS-based version of the interlock rat.

    In June, the researchers found a PHP-based version of the interlock rat used in the wild, which was given using the same Kongtook injector.

    Earlier this month, a significant change in the delivery cover occurred, in which the interlock is now switching to the filefix variation of the clickfix method.

    Interlock filefix attack
    Interlock filefix attack
    Source: DFIR Report

    Filefix is a social engineering attack technique developed by security researcher MR.D0X. It is a development of the clickfix attack, which became one of the most widely planned payload distribution methods compared to the previous year.

    In FileFix variation, the attacker gives weapons to reliable Windows UI elements such as file explorers and HTML applications (.HTA) to trick users to execute malicious powerrashels or JavaScript code without displaying any security warning.

    Users are motivated to “open a file” by pasting copied string into the address bar of the file explorer. The string is a powershell command that is disturbed to look like a file path using comment syntax.

    In recent interlock attacks, the goals are asked to paste the command -up with a fake file path on the file explorer, leading to downloading Php rats from ‘Trycloudflare.com’ and leading to its execution on the system.

    After the infection, the rat executes a series of power sugar commands to gather systems and network information and exfiltrate this data as a structured JSON for the attacker.

    Dfir report Active directory calculation, checking for backup, navigating local directions and evidence of interactive activity including domain controllers are also mentioned.

    Command and Control (C2) can send shell commands to execute the shell command for the server rat, introduce the new payload, add firmness through the registration run key or to move later via remote desktop (RDP).

    The interlock ransomware was launched in September 2024, claiming notable victims such as Texas Tech University, Davita and Catering Health.

    The ransomware operation leveraged the clickfix to infect the goals, but its pivoting for the FileFIX indicates that the attacker is quick to suit the methods of the silent attack.

    This is the first public confirmation of the filefix being used in the actual cyber attack. This is likely to gain more popularity as the danger actors detect ways to include it in their attacks.


    Tines needle

    While cloud attacks can be more sophisticated, the attackers still succeed with surprisingly simple techniques.

    Drawing by the detection of Vij in thousands of organizations, this report reveals the 8 major techniques used by Claude-Floid danger actors.

    adopts FileFix interlock Malware method providing Ransomware
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHow to achieve all ink game feelings – gamezebo
    Next Article As browser warm wars, here are the hottest options for chrome and safari in 2025.
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Anthropic AI wants to stop the model from evil – how is here

    August 4, 2025
    Security

    Fashion giant channel hit salesforce data theft attacks

    August 4, 2025
    Security

    Oauth -pps Für M365-PHISHING MISSBRAUCT | CSO online

    August 4, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Top mobile phones under Rs 15,000 in India (August 2025): Redmi Note 14 SE 5G, Tecno Pova 7, IQoo Z10X, and more

    August 5, 2025

    A top designer was banned from drill. Now he is creating his own contestant.

    August 4, 2025

    Anthropic AI wants to stop the model from evil – how is here

    August 4, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.