Skip to content

Interlock

Interlock is a double-extortion ransomware operation active since at least late 2024.

Profile source: Mallory opens in a new tab

Interlock

Family profile

Interlock is a double-extortion ransomware operation active since at least late 2024. It steals data prior to encryption and pressures victims through a Tor-based leak site and regulatory-themed extortion messaging. Victims have included organizations in healthcare, education, government, manufacturing, engineering, construction, and other critical-infrastructure and enterprise environments across North America and Europe.

Interlock has operated across Windows and virtualization environments including VMware ESXi, and reporting also links it to Linux and FreeBSD/ESXi encryptors. The ransomware family has been associated with a broader intrusion toolkit that includes custom remote-access trojans, credential-harvesting components, reconnaissance scripts, proxying infrastructure, and alternate remote-access software. Observed custom implants include NodeSnake and InterlockRAT, which provide persistent command execution, file transfer, proxying, and redundant access paths.

A recurring initial-access pattern is ClickFix-style social engineering in which a fake CAPTCHA or fake update prompt convinces a user to paste and run a malicious command in Windows. Interlock has also been observed exploiting CVE-2026-20131, a critical Cisco Secure Firewall Management Center remote-code-execution vulnerability, as a zero-day for initial access to enterprise edge infrastructure. After foothold establishment, the group conducts extensive reconnaissance, harvests credentials, moves laterally, tampers with security tooling, and stages data for exfiltration before deploying ransomware.

Observed post-compromise tradecraft includes memory acquisition and credential extraction using legitimate forensic tools, Kerberoasting, NTLM downgrade abuse, scheduled-task persistence, creation of privileged accounts, use of remote administration software for persistence, and deployment of reverse-proxy infrastructure and memory-resident backdoors for evasion and resilience. Interlock activity has also resulted in disruption of hypervisors and broader enterprise operations, consistent with mature multi-stage ransomware intrusions.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

Operational record

19
Indicators
1
YARA rules
4
Ransom notes
2
Leak sites
2 available

Defense Evasion

  • ProcessHacker
  • ThreatFire System Monitor driver (BYOVD)

Discovery Enum

  • Advanced Port Scanner
  • Azure Storage Explorer

Exfiltration

  • AZCopy
  • WinSCP

LOLBAS

  • PsExec

Networking

  • PuTTY

Offsec

  • Cobalt Strike

RMM Tools

  • AnyDesk
  • ScreenConnect

Published indicators

Md5

9 total
  • e11d147dad6e47a1cecb1f2755f95a55
  • f7f679420671b7e18677831d4d276277
  • f76d907ca3817a8b2967790315265469
  • 6c3b2558fc8cfcb2751437b6e5cdeb6f
  • 6d034dca42ffea354a20cd15d3f2ffd5
  • faf9a658f4f9b424be3dab262a8af81c
  • 3104efb23ea174ac5eda9f5fd0e8c077
  • f73005682c1d90f4b3269483b687e891
  • 33d8eabbf428fef8c5cd50b440ee3d07

Url

4 total
  • hxxp://23.95.182.59/31279geuwtoisgdehbiuowaehsgdb/cht
  • hxxp://23.95.182.59/31279geuwtoisgdehbiuowaehsgdb/klg
  • hxxps://apple-online.shop/ChromeSetup.exe
  • hxxps://rvthereyet.com/wp-admin/images/rsggj.php

Sha256

3 total
  • a26f0a2da63a838161a7d335aaa5e4b314a232acc15dcabdb6f6dbec63cda642
  • c9920e995fbc98cd3883ef4c4520300d5e82bab5d2a5c781e9e9fe694a43e82f
  • e86bb8361c436be94b0901e5b39db9b6666134f23cce1e5581421c2981405cb1

Ip

3 total
  • 23.95.182.59
  • 195.201.21.34
  • 159.223.46.184

Recent claims

Reported operators

Threat actors

4 named in public reporting
Interlock

Amazon reported that the Interlock ransomware group has been exploiting the maximum severity vulnerability, CVE-2026-20131... The server hosting the binary was used to distribute malware belonging to the Interlock family.

GOLD EMBRACE

Interlock ransomware is taking a familiar Windows security tool and using it for credential theft.

KongTuke

The Rhysida and Interlock groups, which are known to attack healthcare and other critical infrastructure, have similar TTPs and encryption binaries, leading to some speculation of a connection between the two groups.

Hive0163

The e-crime group is primarily associated with a wide range of malicious tools, including NodeSnake, Interlock RAT, JunkFiction loader, and Interlock ransomware.

Exploited software

Vulnerabilities linked to Interlock

4 CVEs

MITRE ATT&CK

Interlock in ATT&CK

30 distinct techniques

Reporting

Research mentioning Interlock

Aug 10
Cert Dk

Angreb med ransomware rammer universiteter hårdere | DKCERT

Ransomware activity intensified in 2026 as the criminal ecosystem expanded to 146 active groups by midyear, with 61 new groups emerging and public victim counts rising sharply across multiple regions and sectors. Black Kite reported 7,551 victims globally, a 55.1% year-over-year increase in Europe during the first four months of the year, and continued dominance by a small number of operators despite broader fragmentation. Qilin remained the leading ransomware-as-a-service operation across much of the market, benefiting from the decline of rivals such as LockBit and ALPHV, while researchers said attackers frequently gained initial access by exploiting critical vulnerabilities with CVSS >= 9 and, in some cases, through phishing and supply-chain compromise. At the same time, The Gentlemen emerged as one of the fastest-growing threats, especially against higher education. Comparitech counted 104 ransomware attacks against the global education sector in the first half of 2026, with attacks increasingly concentrated on colleges and universities and the United States recording the most confirmed victims. ESET said The Gentlemen equipped affiliates with the GentleKiller framework, a bring-your-own-vulnerable-driver toolkit designed to disable endpoint defenses before encryption, targeting more than 400 processes across roughly 48 security products. The group was also linked to steep growth in university attacks, including a case at Mount Royal University involving a $1.9 million ransom demand, alleged theft of more than 10TB of data, and destructive deletion of drives.

Jul 24
Infosecurity Magazine News

Ransomware Attacks Targeting Universities on the Rise - Infosecurity Magazine

Jul 21
Infosecurity Magazine News

A New Ransomware Threat Actor Emerges Every Week, Warns Report - Infosecurity Magazine

Jul 15
Gurucul Threat Research

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | Community Portal | Gurucul

Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.

Jul 14
Trojan Killer News

Artlist ClickFix Page Dropped a Native Windows RAT

Jul 14
Infostealers Com Infostealers

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | InfoStealers

Jul 14
Malware News

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist - Malware Analysis - Malware Analysis, News and Indicators

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.