logo

Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase

ID: 3bddbfdc-39ca-555e-922d-615ba412921c

STIX ID: report--3bddbfdc-39ca-555e-922d-615ba412921c

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Tushar Subhra Dutta

...
...

Two active ransomware operations, Interlock and Rhysida, have been linked by IBM X-Force research that found they share a private backdoor named Supper and exhibit significant code and tooling overlap. The report describes infection chains using trojanized installers, traffic distribution systems, and fraudulent code signing, highlights post-compromise activity and exploited CVEs, and provides detailed IoCs (IPs, domains, file hashes) and detection recommendations for impacted sectors including healthcare, education, and government.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.