#StopRansomware: Interlock
ID: ac210fba-b688-5a1c-b80d-df8037e09a9a
STIX ID: report--ac210fba-b688-5a1c-b80d-df8037e09a9a
Feed Name: CISA Cybersecurity Advisories
**Executive Summary:** This joint FBI/CISA/HHS/MS-ISAC advisory describes the Interlock ransomware campaign—an opportunistic, financially motivated double‑extortion threat active since September 2024 across North America and Europe—detailing initial access vectors (drive‑by downloads, ClickFix social engineering), post‑compromise actions (PowerShell reconnaissance, persistence, credential theft, RDP/AnyDesk lateral movement), use of RATs/C2 (Cobalt Strike, SystemBC, NodeSnake), file/system IOCs (hashes, filenames, extensions, ransom note), and recommended mitigations mapped to the MITRE ATT&CK framework.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
