Interlock RAT: The Kongtuke Connection Unmasked
In today’s cybersecurity landscape, advanced persistent threats (APTs) like the Interlock RAT are becoming increasingly sophisticated.

Setting the Trap: Kongtuke FileFix Analysis Leads to Interlock RAT

In today’s cybersecurity landscape, advanced persistent threats (APTs) like the Interlock RAT are becoming increasingly sophisticated. By leveraging Linux-based analysis tools, we can effectively identify, track, and neutralize these threats. One such example is the analysis of the Kongtuke FileFix, which revealed the true nature of the Interlock RAT.
Understanding the Threat: Kongtuke Interlock RAT

The Interlock RAT is a remote access tool (RAT) designed to compromise Linux systems. The malware spreads via a malicious ELF file: 28c3c50d115d2b8ffc7ba0a8de9572fbe307907aaae3a486aabd8c0266e9426f.elf. After performing an in-depth analysis, our security experts discovered that the file is a 64-bit ELF executable, statically linked for FreeBSD 10.4 systems, and flagged with a VirusTotal score of 40/65, confirming its malicious nature.
Here’s what we learned:

File Details:
File Name: 28c3c50d115d2b8ffc7ba0a8de9572fbe307907aaae3a486aabd8c0266e9426f.elf
MD5: f76d907ca3817a8b2967790315265469
SHA-1: 8a38825ee33980a27ab6970e090a30a46226f752
SHA-256: 28c3c50d115d2b8ffc7ba0a8de9572fbe307907aaae3a486aabd8c0266e9426f
This statically linked ELF file was specifically crafted to operate under FreeBSD and Linux-based systems. Static linking indicates that external dependencies are baked into the file, making it harder to detect and neutralize.
Malware Hashes and Detections:
The Interlock RAT has been flagged by 40 security vendors, further solidifying its dangerous nature. The file has been submitted to various analysis platforms multiple times, with the latest detection on February 11, 2026.IP Address Analysis:
Associated with this ELF file are the following IP addresses:184.95.51.165
64.95.12.71

These IPs are known to be malicious and are linked to suspicious domains such as:
hxxp://deadly-programming-attorneys-our[.]trycloudflare[.]comexisted-bunch-balance-councils[.]trycloudflare[.]com
Tracking the IP addresses and domains reveals the infrastructure supporting the Interlock RAT‘s communication, aiding in its command and control (C2) operations.
IOC (Indicators of Compromise) to Block
To help organizations protect themselves against the Interlock RAT, it’s crucial to block key indicators of compromise (IoCs). Below is a table containing the critical IoCs you should monitor and block to enhance your defenses:
| IOC Type | IOC |
|---|---|
| File Hash (SHA-256) | 28a9982cf2b4fc53a1545b6ed0d0c1788ca9369a847750f5652ffa0ca7f7b7d3 |
| File Hash (SHA-256) | 8afd6c0636c5d70ac0622396268786190a428635e9cf28ab23add939377727b0 |
| IP Address | 184[.]95[.]51[.]165 |
| IP Address | 64[.]95[.]12[.]71 |
| Malicious URL | hxxp://deadly-programming-attorneys-our[.]trycloudflare[.]com |
| Malicious Hostnames | deadly-programming-attorneys-our[.]trycloudflare[.]com |
| Malicious Hostnames | ferrari-rolling-facilities-lounge[.]trycloudflare[.]com |
| Malicious Hostnames | ranked-accordingly-ab-hired[.]trycloudflare[.]com |
By integrating these IoCs into your security systems and firewalls, you can proactively block attempts from the Interlock RAT and Kongtuke malware infrastructure to infiltrate your network.
What We Found Using Linux Analysis Tools
During our in-depth Linux malware analysis, we used various tools to dissect and map the behavior of the Interlock RAT. Here’s a quick overview of key findings:
File Behavior: The ELF file was observed to create suspicious network connections with command-and-control servers.

Persistence Mechanisms: The malware was configured to maintain persistence by adding itself to critical system directories and startup processes.
Payload Delivery: Upon execution, the Interlock RAT initiated remote access capabilities, allowing attackers to control the compromised machine without detection.
By combining static and dynamic analysis of this ELF file, our team was able to map the interactions between the malware and the host system, identifying its exfiltration patterns and C2 infrastructure.


Why You Need to Act
The Interlock RAT is just one example of the growing threat posed by advanced Linux-based malware. With threats evolving at an alarming rate, it’s critical for organizations to proactively map their infrastructure using the right tools and analysis techniques. Our FileFix analysis and infrastructure mapping services provide the framework necessary to detect, block, and neutralize these threats before they can cause damage.
Secure your network today by using advanced Linux analysis methods and custom threat intelligence to bolster your defense against complex APTs like Interlock RAT.



