Unwrapping the emerging Interlock ransomware attack
ID: b7013908-c7fa-5d4c-b004-de445bdb0c0d
STIX ID: report--b7013908-c7fa-5d4c-b004-de445bdb0c0d
Feed Name: Cisco Talos
Threat Score
Talos IR reports on Interlock, a ransomware group conducting big‑game hunting and double‑extortion: attackers used a fake Chrome updater RAT, PowerShell loaders, a Go-based credential stealer and keylogger, RDP/AnyDesk lateral movement, and AzCopy/Azure Storage Explorer to exfiltrate data before deploying Windows and Linux encryptors that append the .interlock extension; the report includes technical analysis, persistence and deletion routines, overlaps with Rhysida TTPs, and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
