The DFIR Report and Proofpoint have identified a new PHP-based variant of the Interlock ransomware group's RAT, distinct from the previously known JavaScript/Node.js-based NodeSnake. Active since May 2025, the campaign uses KongTuke (LandUpdate808) web-inject clusters to compromise websites with hidden scripts. Victims are lured via fake CAPTCHA prompts that trigger a clipboard-paste attack executing PowerShell, which downloads and runs the PHP-based RAT from the user's AppData directory. The RAT performs automated system reconnaissance (systeminfo, tasklist, ARP table, privilege checks), supports C2 commands for executing EXE/DLL payloads, running shell commands, and establishing persistence via Windows Registry Run keys. It abuses Cloudflare Tunnel URLs to mask C2 infrastructure with hardcoded fallback IPs for resilience. Lateral movement via RDP was also observed. The campaign appears opportunistic across industries. IOCs and detection rules are provided.