Defense Evasion
- ProcessHacker
- ThreatFire System Monitor driver (BYOVD)
Interlock is a double-extortion ransomware operation active since at least late 2024.
Profile source: Mallory opens in a new tabInterlock
Interlock is a double-extortion ransomware operation active since at least late 2024. It steals data prior to encryption and pressures victims through a Tor-based leak site and regulatory-themed extortion messaging. Victims have included organizations in healthcare, education, government, manufacturing, engineering, construction, and other critical-infrastructure and enterprise environments across North America and Europe.
Interlock has operated across Windows and virtualization environments including VMware ESXi, and reporting also links it to Linux and FreeBSD/ESXi encryptors. The ransomware family has been associated with a broader intrusion toolkit that includes custom remote-access trojans, credential-harvesting components, reconnaissance scripts, proxying infrastructure, and alternate remote-access software. Observed custom implants include NodeSnake and InterlockRAT, which provide persistent command execution, file transfer, proxying, and redundant access paths.
A recurring initial-access pattern is ClickFix-style social engineering in which a fake CAPTCHA or fake update prompt convinces a user to paste and run a malicious command in Windows. Interlock has also been observed exploiting CVE-2026-20131, a critical Cisco Secure Firewall Management Center remote-code-execution vulnerability, as a zero-day for initial access to enterprise edge infrastructure. After foothold establishment, the group conducts extensive reconnaissance, harvests credentials, moves laterally, tampers with security tooling, and stages data for exfiltration before deploying ransomware.
Observed post-compromise tradecraft includes memory acquisition and credential extraction using legitimate forensic tools, Kerberoasting, NTLM downgrade abuse, scheduled-task persistence, creation of privileged accounts, use of remote administration software for persistence, and deployment of reverse-proxy infrastructure and memory-resident backdoors for evasion and resilience. Interlock activity has also resulted in disruption of hypervisors and broader enterprise operations, consistent with mature multi-stage ransomware intrusions.
e11d147dad6e47a1cecb1f2755f95a55f7f679420671b7e18677831d4d276277f76d907ca3817a8b29677903152654696c3b2558fc8cfcb2751437b6e5cdeb6f6d034dca42ffea354a20cd15d3f2ffd5faf9a658f4f9b424be3dab262a8af81c3104efb23ea174ac5eda9f5fd0e8c077f73005682c1d90f4b3269483b687e89133d8eabbf428fef8c5cd50b440ee3d07hxxp://23.95.182.59/31279geuwtoisgdehbiuowaehsgdb/chthxxp://23.95.182.59/31279geuwtoisgdehbiuowaehsgdb/klghxxps://apple-online.shop/ChromeSetup.exehxxps://rvthereyet.com/wp-admin/images/rsggj.phpa26f0a2da63a838161a7d335aaa5e4b314a232acc15dcabdb6f6dbec63cda642c9920e995fbc98cd3883ef4c4520300d5e82bab5d2a5c781e9e9fe694a43e82fe86bb8361c436be94b0901e5b39db9b6666134f23cce1e5581421c2981405cb123.95.182.59195.201.21.34159.223.46.184Reported operators
Amazon reported that the Interlock ransomware group has been exploiting the maximum severity vulnerability, CVE-2026-20131... The server hosting the binary was used to distribute malware belonging to the Interlock family.
Interlock ransomware is taking a familiar Windows security tool and using it for credential theft.
The Rhysida and Interlock groups, which are known to attack healthcare and other critical infrastructure, have similar TTPs and encryption binaries, leading to some speculation of a connection between the two groups.
The e-crime group is primarily associated with a wide range of malicious tools, including NodeSnake, Interlock RAT, JunkFiction loader, and Interlock ransomware.
Exploited software
MITRE ATT&CK
Reporting
Ransomware activity intensified in 2026 as the criminal ecosystem expanded to 146 active groups by midyear, with 61 new groups emerging and public victim counts rising sharply across multiple regions and sectors. Black Kite reported 7,551 victims globally, a 55.1% year-over-year increase in Europe during the first four months of the year, and continued dominance by a small number of operators despite broader fragmentation. Qilin remained the leading ransomware-as-a-service operation across much of the market, benefiting from the decline of rivals such as LockBit and ALPHV, while researchers said attackers frequently gained initial access by exploiting critical vulnerabilities with CVSS >= 9 and, in some cases, through phishing and supply-chain compromise. At the same time, The Gentlemen emerged as one of the fastest-growing threats, especially against higher education. Comparitech counted 104 ransomware attacks against the global education sector in the first half of 2026, with attacks increasingly concentrated on colleges and universities and the United States recording the most confirmed victims. ESET said The Gentlemen equipped affiliates with the GentleKiller framework, a bring-your-own-vulnerable-driver toolkit designed to disable endpoint defenses before encryption, targeting more than 400 processes across roughly 48 security products. The group was also linked to steep growth in university attacks, including a case at Mount Royal University involving a $1.9 million ransom demand, alleged theft of more than 10TB of data, and destructive deletion of drives.
Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.