Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors interlock

Description

Interlock is a ransomware group first observed in September 2024 that targets critical infrastructure sectors including healthcare, government, education, and technology across North America and Europe using double-extortion, with 57+ claimed victims including a major US dialysis provider exposing over two million patient records. Known victims: 105 4 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 weeks ago

Executive Summary

Interlock is a medium-sophistication criminal threat actor primarily motivated by organizational gain, focusing on ransomware and financial gain. They have been active since 2023, targeting critical infrastructure sectors in North America and Europe. With over 105 known victims, their tactics include double-extortion, posing a significant risk to sensitive data.

Goals & Targeting

Interlock's strategic objectives are centered around achieving financial gain through ransomware attacks, with a particular focus on sectors that are critical to societal functioning, such as healthcare, government, education, and technology. Their targeting of these sectors in North America and Europe suggests an aim to maximize the impact of their attacks, both in terms of the potential for financial return and the disruption caused to essential services. Typical victims of Interlock include organizations within these sectors that possess sensitive data and are likely to pay ransoms to protect their stakeholders' information and maintain operational continuity.

Enhanced Description

Given the current landscape of ransomware threats, Interlock's emergence and success underscore the evolving tactics, techniques, and procedures (TTPs) of criminal actors. Their focus on double-extortion adds a layer of complexity to their attacks, leveraging both the fear of data loss and the fear of data exposure to pressure victims into complying with their demands. This approach, combined with their targeting of critical infrastructure, positions Interlock as a significant and dangerous threat actor in the cybercrime arena.

Key Capabilities

  • Ransomware Development
  • Double-Extortion Tactics
  • Data Exfiltration
  • Social Engineering
  • Network Exploitation

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Exfiltration

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1204
T1552.001

Software / Tooling

Custom Ransomware
Data Exfiltration Tools
Social Engineering Kits

Campaigns & Victims

Interlock's campaign patterns are marked by a consistent approach to targeting critical infrastructure sectors across North America and Europe. Their operational tempo appears to be sustained, with new victims being added over time. Notable past operations include the compromise of a major US dialysis provider, resulting in the exposure of over two million patient records. This incident, among others, highlights Interlock's capacity for causing significant disruption and data leakage, underscoring the need for proactive defense measures by potential targets.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Unusual network activity indicative of data exfiltration

Recommended Actions

  • Implement robust email filtering and user education programs
  • Enhance network monitoring for signs of unauthorized access or data transfers
  • Regularly back up critical data to secure, isolated storage
  • Deploy anti-ransomware solutions and keep all software up-to-date

Suggested Tags

Ransomware
Criminal
Double-Extortion
Data Breach
Critical Infrastructure

Confidence Assessment

The confidence level in the available data on Interlock is moderate to high, given the clear patterns of their activities and the sectors they target. However, information gaps exist regarding the specific tools and techniques they use, as well as the full scope of their operational capabilities. Further intelligence gathering and analysis are necessary to fully understand the threat posed by Interlock and to develop comprehensive defensive strategies.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 18 URL 2

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

24

Campaigns

117

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Critical Infrastructure
Government Targeting

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Dec 1, 2023
Last Seen
Aug 11, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.