logo

Interlock ransomware evolving under the radar

ID: c4f9c5ef-8cdc-5792-96c0-0bf86b387fa6

STIX ID: report--c4f9c5ef-8cdc-5792-96c0-0bf86b387fa6

Feed Name: Sekoia.io Blog

Threat Score
75/100

Date Published: 2025-04-16

Date Updated: 2026-04-29

Author: Sekoia TDR

...
...

**Interlock ransomware (active since Sep 2024)**: Technical analysis of an evolving ransomware intrusion set that uses compromised websites and fake updaters (PyInstaller), ClickFix social‑engineering, a PowerShell backdoor and a custom RAT to deploy credential stealers and ransomware for Big Game Hunting and double‑extortion; the report provides detailed TTPs, IOCs (file hashes, domains, IPs, URLs), YARA detection rules, and observed victim/DLS behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.