logo

#StopRansomware: Interlock

ID: ac210fba-b688-5a1c-b80d-df8037e09a9a

STIX ID: report--ac210fba-b688-5a1c-b80d-df8037e09a9a

Feed Name: CISA Cybersecurity Advisories

Threat Score
78/100

Date Published: 2025-07-21

Date Updated: 2026-04-19

Author: CISA

...
...

**Executive Summary:** This joint FBI/CISA/HHS/MS-ISAC advisory describes the Interlock ransomware campaign—an opportunistic, financially motivated double‑extortion threat active since September 2024 across North America and Europe—detailing initial access vectors (drive‑by downloads, ClickFix social engineering), post‑compromise actions (PowerShell reconnaissance, persistence, credential theft, RDP/AnyDesk lateral movement), use of RATs/C2 (Cobalt Strike, SystemBC, NodeSnake), file/system IOCs (hashes, filenames, extensions, ransom note), and recommended mitigations mapped to the MITRE ATT&CK framework.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.