logo

Emerging Threat Actor: Interlock Ransomware

ID: c85242d1-4079-5c42-a14a-c7b0b663deda

STIX ID: report--c85242d1-4079-5c42-a14a-c7b0b663deda

Feed Name: Halcyon Blog

Threat Score
80/100

Date Published: 2025-07-23

Date Updated: 2026-04-28

...
...

Interlock is a rapidly evolving, highly disruptive ransomware-as-a-service operation descended from Rhysida that conducts destructive double-extortion attacks across Windows and Linux. The group leverages stolen credentials and IABs for initial access, deploys custom loaders and a newly observed PHP-based RAT, uses credential theft tools (e.g., Mimikatz), sabotages recovery (deleting shadow copies, halting backups), and hosts leaked data to pressure victims; it operates via a closed affiliate model, has been linked to 60–80+ intrusions spanning professional services, education, manufacturing, healthcare and retail, and issues tailored ransom demands ranging from hundreds of thousands to several million dollars.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.