Description Summary
Interlock ransomware emerged in late September 2024 and rapidly rose to prominence with attacks on healthcare, technology, and government targets. It uses double extortion via the 'Worldwide Secrets Blog' leak site. Interlock has both Windows and Linux/FreeBSD encryptors and uses unusual social-engineering vectors including ClickFix-style fake browser updates.
Threat Actor
Closed group with operators distinct from but possibly overlapping with the Rhysida cluster. ClickFix social engineering and exposed RDP are common entry points.
Technical Indicators
Encryption Extension
.interlock
Encryption Algorithm
AES + RSA
Ransom Note Name
!__README__!.txt
Targeted Industries
Healthcare, Technology, Government, Manufacturing
First Seen
September 2024
Last Seen
Active
Geographical Location
United States, Europe
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| Execution x 2 | T1059 | Command and Scripting Interpreter |
| T1204.001 | User Execution: Malicious Link (ClickFix) | |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 3 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop |