logo

Meet Interlock — The new ransomware targeting FreeBSD servers

ID: ca1da649-da8d-514d-b246-5a20d6a55b2a

STIX ID: report--ca1da649-da8d-514d-b246-5a20d6a55b2a

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-11-03

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

**Interlock ransomware** is a recently observed ransomware operation that targets organizations worldwide and uniquely includes a FreeBSD ELF encryptor alongside Windows variants; victims (including Wayne County, Michigan) have had data stolen and published when ransoms were not paid. Researchers observed indicators such as the .interlock file extension, a ransom note named !__README__!.txt, Windows behaviors (event log clearing, optional self-deletion via rundll32), and a Tor negotiation/data-leak site used for double-extortion and negotiations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.