K7 Security Labs reported a Python-based remote access trojan (PyRAT) targeting both Windows and Linux, discovered via VirusTotal as a Python ELF binary packaged with PyInstaller (Python 2.7). The malware fingerprints hosts (OS, hostname, username) and communicates with its C2 over unencrypted HTTP to support remote command execution, file theft, and screenshot capture. Persistence differs by OS: on Linux it creates an autostart entry at ~/.config/autostart/dpkgn.desktop (masquerading as Debian tooling), while on Windows it adds a user-level Run key entry (e.g., under HKCU\...\Run with the value name “lee”).
FortiGuard Labs detailed ongoing activity from the Interlock ransomware group, describing a financially motivated operation impacting primarily UK- and US-based organizations, with notable focus on the education sector. Fortinet assesses Interlock as a smaller, non-RaaS group that develops and operates its own tooling across much of the kill chain, and notes that early-stage indicators in a recent intrusion align with prior reporting by eSentire and elements of the Interlock ecosystem previously documented by Mandiant—reinforcing the need for proactive threat hunting to detect intrusions before data theft and encryption occur.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
On January 29, 2026, K7 Security Labs disclosed a new Python-based remote access trojan targeting both Windows and Linux, with capabilities including command execution, file transfer, screenshot capture, and ZIP-based bulk exfiltration. Researchers said the malware used unencrypted HTTP POST requests with JSON data and platform-specific persistence mechanisms.
On January 29, 2026, FortiGuard Labs published technical findings on the 2025 Interlock intrusion, including use of the Hotta Killer BYOVD tool abusing CVE-2025-61155 and a custom infostealer named move.dll. The company said it provided indicators of compromise and shared details with law enforcement.
In October 2025, the threat actor prepared for and executed ransomware deployment, encrypting Nutanix systems with an ELF payload over SSH and Windows endpoints with a JavaScript ransomware launched using a dropped javaw.exe. The attack added distinct file extensions and left ransom notes on affected systems.
In September 2025, the Interlock actor resumed operations in the victim environment, deployed multiple RAT instances, used scheduled tasks for persistence, enabled RDP, and installed ScreenConnect for GUI-based access. The actor browsed and staged data, then used AZcopy to exfiltrate more than 250GB from the primary file server to an Azure storage bucket.
FortiGuard Incident Response said a 2025 intrusion attributed to the Interlock ransomware group began on March 31, 2025, when a MintLoader-driven PowerShell download cradle deployed a Node.js runtime and a JavaScript RAT. The malware established persistence through an autorun entry and later expanded to additional Interlock RAT implants.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 32 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcefeeds.fortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.