Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase
ID: 3bddbfdc-39ca-555e-922d-615ba412921c
STIX ID: report--3bddbfdc-39ca-555e-922d-615ba412921c
Feed Name: cybersecurityNews.com
Two active ransomware operations, Interlock and Rhysida, have been linked by IBM X-Force research that found they share a private backdoor named Supper and exhibit significant code and tooling overlap. The report describes infection chains using trojanized installers, traffic distribution systems, and fraudulent code signing, highlights post-compromise activity and exploited CVEs, and provides detailed IoCs (IPs, domains, file hashes) and detection recommendations for impacted sectors including healthcare, education, and government.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
