logo

Interlock Ransomware: New Techniques, Same Old Tricks

ID: f0ca7c20-a64f-591c-ad0e-193494d90f1d

STIX ID: report--f0ca7c20-a64f-591c-ad0e-193494d90f1d

Feed Name: Fortinet Blog

Threat Score
85/100

Date Published: 2026-01-29

Date Updated: 2026-04-27

...
...

**Executive Summary:** FortiGuard documents a multi-stage Interlock ransomware intrusion against an education-sector organization that began with a MintLoader PowerShell download, progressed through NodeSnakeRAT/Interlock RAT implants and credential harvesting, included bulk exfiltration (~250GB) using AZCopy and ScreenConnect-assisted RDP, and culminated in large-scale encryption of Windows hosts and Nutanix storage (using both JavaScript and ELF ransomware), while the adversary employed a BYOVD 'Hotta Killer' driver to attempt to disable Fortinet defenses; the report provides detailed malware analysis, IOCs, MITRE mappings, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.