Defense Evasion
- ProcessHacker
- ThreatFire System Monitor driver (BYOVD)
Interlock is a double-extortion ransomware operation active since at least late 2024.
Profile source: Mallory opens in a new tabInterlock
Interlock is a double-extortion ransomware operation active since at least late 2024. The group steals data before encryption and pressures victims through a Tor-based leak site and regulatory-themed extortion messaging. Interlock has targeted organizations in North America and Europe, including healthcare, education, government, manufacturing, engineering, construction, and other critical infrastructure sectors. Public reporting has linked the operation to incidents affecting municipal government and healthcare organizations, including large-scale data theft cases.
Interlock is notable for using multiple initial-access paths. A frequently reported method is ClickFix-style social engineering in which fake CAPTCHA or fake update prompts convince a user to paste and run malicious commands in Windows, leading to PowerShell execution and deployment of follow-on malware. Interlock has also been observed exploiting CVE-2026-20131, a critical remote code execution vulnerability in Cisco Secure Firewall Management Center, giving it a zero-day foothold against enterprise firewall management infrastructure before public disclosure.
Post-compromise activity shows a mature, multi-stage intrusion model. Interlock conducts extensive reconnaissance, harvests credentials, and moves laterally through Windows environments, including toward domain controllers and virtualization infrastructure. Reported tooling and tradecraft include memory acquisition and analysis for credential extraction, Kerberoasting, NTLM downgrade abuse, creation of new privileged accounts, scheduled-task persistence, tampering with security tools, and theft of cloud and on-premises credentials. The operation has used custom remote access tooling including NodeSnake and InterlockRAT, along with alternate remote-access mechanisms to preserve access and support command execution, file transfer, proxying, and evasion.
Interlock has been observed operating across Windows, Linux, and virtualized environments including VMware ESXi and FreeBSD-based targets. Its ransomware component encrypts victim data after exfiltration, and reporting indicates the group has disrupted hypervisors and broader enterprise operations during attacks. The malware ecosystem associated with Interlock includes credential-harvesting components, persistent backdoors, reconnaissance scripts, and ransomware payloads, reflecting an intrusion set designed for sustained access, data theft, lateral movement, and final-stage extortion.
e11d147dad6e47a1cecb1f2755f95a55f7f679420671b7e18677831d4d276277f76d907ca3817a8b29677903152654696c3b2558fc8cfcb2751437b6e5cdeb6f6d034dca42ffea354a20cd15d3f2ffd5faf9a658f4f9b424be3dab262a8af81c3104efb23ea174ac5eda9f5fd0e8c077f73005682c1d90f4b3269483b687e89133d8eabbf428fef8c5cd50b440ee3d07hxxp://23.95.182.59/31279geuwtoisgdehbiuowaehsgdb/chthxxp://23.95.182.59/31279geuwtoisgdehbiuowaehsgdb/klghxxps://apple-online.shop/ChromeSetup.exehxxps://rvthereyet.com/wp-admin/images/rsggj.phpa26f0a2da63a838161a7d335aaa5e4b314a232acc15dcabdb6f6dbec63cda642c9920e995fbc98cd3883ef4c4520300d5e82bab5d2a5c781e9e9fe694a43e82fe86bb8361c436be94b0901e5b39db9b6666134f23cce1e5581421c2981405cb123.95.182.59195.201.21.34159.223.46.184Reported operators
Interlock ransomware is taking a familiar Windows security tool and using it for credential theft.
The Rhysida and Interlock groups, which are known to attack healthcare and other critical infrastructure, have similar TTPs and encryption binaries, leading to some speculation of a connection between the two groups.
Amazon’s threat intelligence teams have uncovered a new cyber campaign linked to the Interlock ransomware group... The recovered malware and artifacts were attributed to the Interlock ransomware family based on several consistent indicators.
The e-crime group is primarily associated with a wide range of malicious tools, including NodeSnake, Interlock RAT, JunkFiction loader, and Interlock ransomware.
Exploited software
MITRE ATT&CK
Reporting
Ransomware activity intensified in 2026 as the criminal ecosystem expanded to 146 active groups by midyear, with 61 new groups emerging and public victim counts rising sharply across multiple regions and sectors. Black Kite reported 7,551 victims globally, a 55.1% year-over-year increase in Europe during the first four months of the year, and continued dominance by a small number of operators despite broader fragmentation. Qilin remained the leading ransomware-as-a-service operation across much of the market, benefiting from the decline of rivals such as LockBit and ALPHV, while researchers said attackers frequently gained initial access by exploiting critical vulnerabilities with CVSS >= 9 and, in some cases, through phishing and supply-chain compromise. At the same time, The Gentlemen emerged as one of the fastest-growing threats, especially against higher education. Comparitech counted 104 ransomware attacks against the global education sector in the first half of 2026, with attacks increasingly concentrated on colleges and universities and the United States recording the most confirmed victims. ESET said The Gentlemen equipped affiliates with the GentleKiller framework, a bring-your-own-vulnerable-driver toolkit designed to disable endpoint defenses before encryption, targeting more than 400 processes across roughly 48 security products. The group was also linked to steep growth in university attacks, including a case at Mount Royal University involving a $1.9 million ransom demand, alleged theft of more than 10TB of data, and destructive deletion of drives.
Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.