Skip to content

Interlock

Interlock is a double-extortion ransomware operation active since at least late 2024.

Profile source: Mallory opens in a new tab

Interlock

Family profile

Interlock is a double-extortion ransomware operation active since at least late 2024. The group steals data before encryption and pressures victims through a Tor-based leak site and regulatory-themed extortion messaging. Interlock has targeted organizations in North America and Europe, including healthcare, education, government, manufacturing, engineering, construction, and other critical infrastructure sectors. Public reporting has linked the operation to incidents affecting municipal government and healthcare organizations, including large-scale data theft cases.

Interlock is notable for using multiple initial-access paths. A frequently reported method is ClickFix-style social engineering in which fake CAPTCHA or fake update prompts convince a user to paste and run malicious commands in Windows, leading to PowerShell execution and deployment of follow-on malware. Interlock has also been observed exploiting CVE-2026-20131, a critical remote code execution vulnerability in Cisco Secure Firewall Management Center, giving it a zero-day foothold against enterprise firewall management infrastructure before public disclosure.

Post-compromise activity shows a mature, multi-stage intrusion model. Interlock conducts extensive reconnaissance, harvests credentials, and moves laterally through Windows environments, including toward domain controllers and virtualization infrastructure. Reported tooling and tradecraft include memory acquisition and analysis for credential extraction, Kerberoasting, NTLM downgrade abuse, creation of new privileged accounts, scheduled-task persistence, tampering with security tools, and theft of cloud and on-premises credentials. The operation has used custom remote access tooling including NodeSnake and InterlockRAT, along with alternate remote-access mechanisms to preserve access and support command execution, file transfer, proxying, and evasion.

Interlock has been observed operating across Windows, Linux, and virtualized environments including VMware ESXi and FreeBSD-based targets. Its ransomware component encrypts victim data after exfiltration, and reporting indicates the group has disrupted hypervisors and broader enterprise operations during attacks. The malware ecosystem associated with Interlock includes credential-harvesting components, persistent backdoors, reconnaissance scripts, and ransomware payloads, reflecting an intrusion set designed for sustained access, data theft, lateral movement, and final-stage extortion.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

Operational record

19
Indicators
1
YARA rules
4
Ransom notes
2
Leak sites
2 available

Defense Evasion

  • ProcessHacker
  • ThreatFire System Monitor driver (BYOVD)

Discovery Enum

  • Advanced Port Scanner
  • Azure Storage Explorer

Exfiltration

  • AZCopy
  • WinSCP

LOLBAS

  • PsExec

Networking

  • PuTTY

Offsec

  • Cobalt Strike

RMM Tools

  • AnyDesk
  • ScreenConnect

Published indicators

Md5

9 total
  • e11d147dad6e47a1cecb1f2755f95a55
  • f7f679420671b7e18677831d4d276277
  • f76d907ca3817a8b2967790315265469
  • 6c3b2558fc8cfcb2751437b6e5cdeb6f
  • 6d034dca42ffea354a20cd15d3f2ffd5
  • faf9a658f4f9b424be3dab262a8af81c
  • 3104efb23ea174ac5eda9f5fd0e8c077
  • f73005682c1d90f4b3269483b687e891
  • 33d8eabbf428fef8c5cd50b440ee3d07

Url

4 total
  • hxxp://23.95.182.59/31279geuwtoisgdehbiuowaehsgdb/cht
  • hxxp://23.95.182.59/31279geuwtoisgdehbiuowaehsgdb/klg
  • hxxps://apple-online.shop/ChromeSetup.exe
  • hxxps://rvthereyet.com/wp-admin/images/rsggj.php

Sha256

3 total
  • a26f0a2da63a838161a7d335aaa5e4b314a232acc15dcabdb6f6dbec63cda642
  • c9920e995fbc98cd3883ef4c4520300d5e82bab5d2a5c781e9e9fe694a43e82f
  • e86bb8361c436be94b0901e5b39db9b6666134f23cce1e5581421c2981405cb1

Ip

3 total
  • 23.95.182.59
  • 195.201.21.34
  • 159.223.46.184

Recent claims

Reported operators

Threat actors

4 named in public reporting
GOLD EMBRACE

Interlock ransomware is taking a familiar Windows security tool and using it for credential theft.

KongTuke

The Rhysida and Interlock groups, which are known to attack healthcare and other critical infrastructure, have similar TTPs and encryption binaries, leading to some speculation of a connection between the two groups.

Interlock

Amazon’s threat intelligence teams have uncovered a new cyber campaign linked to the Interlock ransomware group... The recovered malware and artifacts were attributed to the Interlock ransomware family based on several consistent indicators.

Hive0163

The e-crime group is primarily associated with a wide range of malicious tools, including NodeSnake, Interlock RAT, JunkFiction loader, and Interlock ransomware.

Exploited software

Vulnerabilities linked to Interlock

4 CVEs

MITRE ATT&CK

Interlock in ATT&CK

30 distinct techniques

Reporting

Research mentioning Interlock

Aug 10
Cert Dk

Angreb med ransomware rammer universiteter hårdere | DKCERT

Ransomware activity intensified in 2026 as the criminal ecosystem expanded to 146 active groups by midyear, with 61 new groups emerging and public victim counts rising sharply across multiple regions and sectors. Black Kite reported 7,551 victims globally, a 55.1% year-over-year increase in Europe during the first four months of the year, and continued dominance by a small number of operators despite broader fragmentation. Qilin remained the leading ransomware-as-a-service operation across much of the market, benefiting from the decline of rivals such as LockBit and ALPHV, while researchers said attackers frequently gained initial access by exploiting critical vulnerabilities with CVSS >= 9 and, in some cases, through phishing and supply-chain compromise. At the same time, The Gentlemen emerged as one of the fastest-growing threats, especially against higher education. Comparitech counted 104 ransomware attacks against the global education sector in the first half of 2026, with attacks increasingly concentrated on colleges and universities and the United States recording the most confirmed victims. ESET said The Gentlemen equipped affiliates with the GentleKiller framework, a bring-your-own-vulnerable-driver toolkit designed to disable endpoint defenses before encryption, targeting more than 400 processes across roughly 48 security products. The group was also linked to steep growth in university attacks, including a case at Mount Royal University involving a $1.9 million ransom demand, alleged theft of more than 10TB of data, and destructive deletion of drives.

Jul 24
Infosecurity Magazine News

Ransomware Attacks Targeting Universities on the Rise - Infosecurity Magazine

Jul 21
Infosecurity Magazine News

A New Ransomware Threat Actor Emerges Every Week, Warns Report - Infosecurity Magazine

Jul 15
Gurucul Threat Research

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | Community Portal | Gurucul

Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.

Jul 14
Trojan Killer News

Artlist ClickFix Page Dropped a Native Windows RAT

Jul 14
Infostealers Com Infostealers

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | InfoStealers

Jul 14
Malware News

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist - Malware Analysis - Malware Analysis, News and Indicators

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.