Description
Interlock is a ransomware operation targeting critical infrastructure and other organizations, first observed in September 2024 in big game hunting and double extortion campaigns. Its affiliates use ClickFix style social engineering and exposed services to gain initial access, steal data, and encrypt Windows and Linux systems. The group's growth has been rapid, and it continues to expand its tooling across platforms.
Stats
- First seen
- October 2024
- Last seen
- October 2026
Also known as
InterLock
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Ransom.Interlock.4 |
| Linux.Ransomware.Interlock |
| Linux.Trojan.Interlock |
| Script-PowerShell.Trojan.Interlock |
| Script-Python.Trojan.Interlock |
| Trojan.Linux.Ransom.InterLock |
| Trojan.Ransom.InterLock.2 |
| Trojan.Ransom.Interlock.A |
| Trojan.Ransom.Interlock.B |
| Trojan.Ransom.Interlock.C |