logo

Unwrapping the emerging Interlock ransomware attack

ID: b7013908-c7fa-5d4c-b004-de445bdb0c0d

STIX ID: report--b7013908-c7fa-5d4c-b004-de445bdb0c0d

Feed Name: Cisco Talos

Threat Score
75/100

Date Published: 2024-11-07

Date Updated: 2026-04-27

Author: Elio Biasiotto

...
...

Talos IR reports on Interlock, a ransomware group conducting big‑game hunting and double‑extortion: attackers used a fake Chrome updater RAT, PowerShell loaders, a Go-based credential stealer and keylogger, RDP/AnyDesk lateral movement, and AzCopy/Azure Storage Explorer to exfiltrate data before deploying Windows and Linux encryptors that append the .interlock extension; the report includes technical analysis, persistence and deletion routines, overlaps with Rhysida TTPs, and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.