Interlock Ransomware Strikes: eSentire Exposes Multi-Stage Payload and ClickFix Social Engineering
ID: 4fe254cc-91a3-5764-a516-df3117c0db98
STIX ID: report--4fe254cc-91a3-5764-a516-df3117c0db98
Feed Name: securityonline.info
Threat Score
eSentire TRU analysis details an active, technically sophisticated Interlock Group ransomware campaign (active since at least Sept 2024) that uses compromised websites and a ClickFix lure to deliver obfuscated PowerShell, a PHP backdoor, and NodeSnake RAT; attackers harvest and exfiltrate sensitive files (base64 + XOR/Gzip), maintain primary and backup C2 mechanisms (including hiskeow.tmp), and leverage LOLBins, Node.js, and custom obfuscation for persistence and execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
