interlock
· Published 20/12/2025 08:54 · Modified 13/03/2026 10:45
· Source: Ransomware.Live
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 08:54
- Modified
- 13/03/2026 10:45
- Updated at
- 13/03/2026 10:45
- Revoked
- No
- Author / Source
- Ransomware.Live
- Resource level
- —
- Primary motivation
- —
- Related entities
- 8 reports, 61 attack patterns (mitre), 14 malware, 9 sectors, 11 countries, 100 indicators, 1 vulnerabilities (cve), 11 organization
Description
No description available
Marking (TLP)
TLP:CLEAR
Labels
ransomware
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (8)
-
1 CVE 10 MITREs 4 Malwares 8 Observables 1 APTPublished 30/01/2026 08:23 · Modified 30/01/2026 08:50
-
7 MITREs 1 Malware 1 APTPublished 29/08/2025 20:20 · Modified 01/09/2025 08:32
-
11 MITREs 4 Malwares 24 Observables 1 APTPublished 15/08/2025 19:40 · Modified 15/08/2025 20:49
-
16 MITREs 2 Malwares 12 Observables 1 APTPublished 15/07/2025 08:57 · Modified 15/07/2025 09:46
-
11 MITREs 4 Malwares 1 APTPublished 16/04/2025 14:00 · Modified 16/04/2025 14:51
-
5 MITREs 1 Malware 1 APTPublished 28/01/2025 18:12 · Modified 29/01/2025 17:02
-
11 MITREs 1 Malware 5 Observables 1 APTPublished 03/12/2024 16:17 · Modified 03/12/2024 16:50
-
15 MITREs 2 Malwares 2 Observables 1 APTPublished 07/11/2024 16:41 · Modified 07/11/2024 21:07
Attack patterns (MITRE) (61)
-
T1204.002 usesMalicious File
-
T1112 usesModify Registry
-
T1571 usesNon-Standard Port
-
T1485 usesData Destruction
-
T1027 usesObfuscated Files or Information
-
T1059.007 usesJavaScript
-
T1055 usesProcess Injection
-
T1059.003 usesWindows Command Shell
-
T1518 usesSoftware Discovery
-
T1048 usesExfiltration Over Alternative Protocol
-
T1486 usesData Encrypted for Impact
-
T1210 usesExploitation of Remote Services
Malware (14)
-
NodeSnakeRAT usesFamilyPublished 30/01/2026 08:23 · Modified 30/01/2026 08:23
-
BerserkStealer usesFamilyPublished 16/04/2025 14:00 · Modified 16/04/2025 14:00
-
Hotta Killer usesFamilyPublished 30/01/2026 08:23 · Modified 30/01/2026 08:23
-
Rhysida usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
SystemBC usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
NodeSnake RAT usesFamilyPublished 15/08/2025 19:40 · Modified 15/08/2025 19:40
-
Interlock RAT usesFamilyPublished 15/08/2025 19:40 · Modified 15/08/2025 19:40
-
Lumma Stealer usesFamilyPublished 08/06/2026 19:36 · Modified 08/06/2026 19:36
-
NodeSnake usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
MintLoader usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
InterlockRAT usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
Sectors (9)
- Public Sector targets
- Construction targets
- Manufacturing targets
- Healthcare targets
- Finance targets
- Hospitality targets
- Government targets
- Technology targets
- Education targets
Countries (11)
- Japan targets
- Italy targets
- Virgin Islands, U.S. targets
- United States of America targets
- Peru targets
- Germany targets
- Australia targets
- Mexico targets
- British Indian Ocean Territory targets
- India targets
- Canada targets
Indicators (100)
-
e307d3e9b8de59311c692b2ab0ee864f0d469066e041141d577b65b43a4b3ffaindicates -
45.61.136.109indicates -
2mail.coindicates -
0fff8fb05cee8dc4a4f7a8f23fa2d67571f360a3025b6d515f9ef37dfdb4e2eaindicates -
views-ethics-orientation-roommate.trycloudflare.comindicates -
santa-reflection-capitol-classifieds.trycloudflare.comindicates -
spa-step-hopkins-islands.trycloudflare.comindicates -
3e4407dfd827714a66e25c2baccefd915233eeec8fb093257e458f4153778beeindicates -
https://album-anthony-rn-submission.trycloudflare.com/25423565indicates -
eb1cdf3118271d754cf0a1777652f83c3d11dc1f9a2b51e81e37602c43b47692indicates -
https://airbluefootgear.com/wp-includes/images/xits.phpindicates -
securities-variance-vocal-temporal.trycloudflare.comindicates
Vulnerabilities (CVE) (1)
5.5
Medium
The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A user-mode process …
- Attack vector
- LOCAL
- Published
- 28/10/2025
- Modified
- 30/01/2026
Organization (11)
- Swartz Campbell targets
- Westlake Christian Academy targets
- Delta Manufacturing targets
- Hunneman targets
- RGD Consulting Engineers targets
- Clarksville ISD targets
- Apex Spine and Neurosurgery targets
- Wagon Mound Public Schools targets
- Elliott-Lewis targets
- Aero Fabrications targets
- The Salvation Army targets