logo

Interlock ransomware: Evolving under the radar with ClickFix

ID: a6590672-b13a-5a63-98d2-40ae3922ae3e

STIX ID: report--a6590672-b13a-5a63-98d2-40ae3922ae3e

Feed Name: Sekoia.com

Threat Score
75/100

Date Published: 2025-04-16

Date Updated: 2026-07-20

...
...

This report details the Interlock ransomware intrusion set (active since Sept 2024), describing its multi-stage attacks that use fake browser/security updaters and ClickFix social-engineering to deliver a PowerShell backdoor, credential stealers (Lumma/Berserk), a custom-packed RAT, and a C/C++ ransomware for Windows and Linux; it includes TTPs for persistence, lateral movement, exfiltration, ransom notes, IoCs (hashes, domains, IPs, URLs), and YARA rules to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.