Interlock is a ransomware group first observed in September 2024 that targets critical infrastructure sectors including healthcare, government, education, and technology across North America and Europe using double-extortion, with 57+ claimed victims including a major US dialysis provider exposing over two million patient records. Known victims: 105 4 ransom note(s) on file
Objectives
Executive Summary
Interlock is a medium-sophistication criminal threat actor primarily motivated by organizational gain, focusing on ransomware and financial gain. They have been active since 2023, targeting critical infrastructure sectors in North America and Europe. With over 105 known victims, their tactics include double-extortion, posing a significant risk to sensitive data.
Goals & Targeting
Interlock's strategic objectives are centered around achieving financial gain through ransomware attacks, with a particular focus on sectors that are critical to societal functioning, such as healthcare, government, education, and technology. Their targeting of these sectors in North America and Europe suggests an aim to maximize the impact of their attacks, both in terms of the potential for financial return and the disruption caused to essential services. Typical victims of Interlock include organizations within these sectors that possess sensitive data and are likely to pay ransoms to protect their stakeholders' information and maintain operational continuity.
Enhanced Description
Given the current landscape of ransomware threats, Interlock's emergence and success underscore the evolving tactics, techniques, and procedures (TTPs) of criminal actors. Their focus on double-extortion adds a layer of complexity to their attacks, leveraging both the fear of data loss and the fear of data exposure to pressure victims into complying with their demands. This approach, combined with their targeting of critical infrastructure, positions Interlock as a significant and dangerous threat actor in the cybercrime arena.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Interlock's campaign patterns are marked by a consistent approach to targeting critical infrastructure sectors across North America and Europe. Their operational tempo appears to be sustained, with new victims being added over time. Notable past operations include the compromise of a major US dialysis provider, resulting in the exposure of over two million patient records. This incident, among others, highlights Interlock's capacity for causing significant disruption and data leakage, underscoring the need for proactive defense measures by potential targets.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data on Interlock is moderate to high, given the clear patterns of their activities and the sectors they target. However, information gaps exist regarding the specific tools and techniques they use, as well as the full scope of their operational capabilities. Further intelligence gathering and analysis are necessary to fully understand the threat posed by Interlock and to develop comprehensive defensive strategies.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
24
Campaigns
117
IOCs
0
Observed Data
0
Tactics