logo

Interlock Ransomware Strikes: eSentire Exposes Multi-Stage Payload and ClickFix Social Engineering

ID: 4fe254cc-91a3-5764-a516-df3117c0db98

STIX ID: report--4fe254cc-91a3-5764-a516-df3117c0db98

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2025-08-02

Date Updated: 2026-04-22

Author: Ddos

...
...

eSentire TRU analysis details an active, technically sophisticated Interlock Group ransomware campaign (active since at least Sept 2024) that uses compromised websites and a ClickFix lure to deliver obfuscated PowerShell, a PHP backdoor, and NodeSnake RAT; attackers harvest and exfiltrate sensitive files (base64 + XOR/Gzip), maintain primary and backup C2 mechanisms (including hiskeow.tmp), and leverage LOLBins, Node.js, and custom obfuscation for persistence and execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.