logo

Interlock Ransomware Analysis, Simulation, and Mitigation - CISA Alert AA25-203A

ID: 70faa787-5e1f-545f-ac39-e8805df687c5

STIX ID: report--70faa787-5e1f-545f-ac39-e8805df687c5

Feed Name: Resources-2

Threat Score
75/100

Date Published: 2025-07-23

Date Updated: 2026-07-22

Author: Huseyin Can YUCEEL

...
...

Interlock is a financially motivated ransomware group active since late 2024 that targets organizations (including critical infrastructure) across North America and Europe using double-extortion tactics: credential harvesting and data exfiltration (often to Azure blobs) followed by AES/RSA encryption of files (extensions .interlock and .1nt3rlock). The report maps Interlock activity to MITRE ATT&CK (drive-by downloads, malicious PowerShell via a "ClickFix" social-engineering trick, Cobalt Strike, AnyDesk, AzCopy, custom stealers, and cleanup evasion), lists observable artifacts (conhost.exe, !__README__!.txt, registry Run keys), and recommends defensive testing and mitigations while referencing a CISA advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.