Interlock Ransomware

Description Summary

Interlock ransomware emerged in late September 2024 and rapidly rose to prominence with attacks on healthcare, technology, and government targets. It uses double extortion via the 'Worldwide Secrets Blog' leak site. Interlock has both Windows and Linux/FreeBSD encryptors and uses unusual social-engineering vectors including ClickFix-style fake browser updates.

Threat Actor

Closed group with operators distinct from but possibly overlapping with the Rhysida cluster. ClickFix social engineering and exposed RDP are common entry points.

Technical Indicators

Encryption Extension
.interlock
Encryption Algorithm
AES + RSA
Ransom Note Name
!__README__!.txt
Targeted Industries
Healthcare, Technology, Government, Manufacturing
First Seen
September 2024
Last Seen
Active
Geographical Location
United States, Europe

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 2 T1059 Command and Scripting Interpreter
T1204.001 User Execution: Malicious Link (ClickFix)
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop