Interlock ransomware evolving under the radar
ID: c4f9c5ef-8cdc-5792-96c0-0bf86b387fa6
STIX ID: report--c4f9c5ef-8cdc-5792-96c0-0bf86b387fa6
Feed Name: Sekoia.io Blog
Threat Score
**Interlock ransomware (active since Sep 2024)**: Technical analysis of an evolving ransomware intrusion set that uses compromised websites and fake updaters (PyInstaller), ClickFix social‑engineering, a PowerShell backdoor and a custom RAT to deploy credential stealers and ransomware for Big Game Hunting and double‑extortion; the report provides detailed TTPs, IOCs (file hashes, domains, IPs, URLs), YARA detection rules, and observed victim/DLS behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
