Netskope Threat Labs

Interlock

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Interlock is a ransomware operation targeting critical infrastructure and other organizations, first observed in September 2024 in big game hunting and double extortion campaigns. Its affiliates use ClickFix style social engineering and exposed services to gain initial access, steal data, and encrypt Windows and Linux systems. The group's growth has been rapid, and it continues to expand its tooling across platforms.

First seen
October 2024
Last seen
October 2026
InterLock
Alert Name
Gen:Variant.Ransom.Interlock.4
Linux.Ransomware.Interlock
Linux.Trojan.Interlock
Script-PowerShell.Trojan.Interlock
Script-Python.Trojan.Interlock
Trojan.Linux.Ransom.InterLock
Trojan.Ransom.InterLock.2
Trojan.Ransom.Interlock.A
Trojan.Ransom.Interlock.B
Trojan.Ransom.Interlock.C