Interlock Ransomware Analysis, Simulation, and Mitigation - CISA Alert AA25-203A
ID: 70faa787-5e1f-545f-ac39-e8805df687c5
STIX ID: report--70faa787-5e1f-545f-ac39-e8805df687c5
Feed Name: Resources-2
Interlock is a financially motivated ransomware group active since late 2024 that targets organizations (including critical infrastructure) across North America and Europe using double-extortion tactics: credential harvesting and data exfiltration (often to Azure blobs) followed by AES/RSA encryption of files (extensions .interlock and .1nt3rlock). The report maps Interlock activity to MITRE ATT&CK (drive-by downloads, malicious PowerShell via a "ClickFix" social-engineering trick, Cobalt Strike, AnyDesk, AzCopy, custom stealers, and cleanup evasion), lists observable artifacts (conhost.exe, !__README__!.txt, registry Run keys), and recommends defensive testing and mitigations while referencing a CISA advisory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
