interlock
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 08:54
- Modified
- 13/03/2026 10:45
- Updated at
- 13/03/2026 10:45
- Revoked
- No
- Author / Source
- Ransomware.Live
- Resource level
- —
- Primary motivation
- —
- Related entities
- 8 reports, 61 attack patterns (mitre), 14 malware, 9 sectors, 11 countries, 100 indicators, 1 vulnerabilities (cve), 11 organization
Description
Marking (TLP)
TLP:CLEAR
Labels
ransomware
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (8)
-
1 CVE 10 MITREs 4 Malwares 8 Observables 1 APT
-
7 MITREs 1 Malware 1 APT
-
11 MITREs 4 Malwares 24 Observables 1 APT
-
16 MITREs 2 Malwares 12 Observables 1 APT
-
11 MITREs 4 Malwares 1 APT
-
5 MITREs 1 Malware 1 APT
-
11 MITREs 1 Malware 5 Observables 1 APT
-
15 MITREs 2 Malwares 2 Observables 1 APT
Attack patterns (MITRE) (61)
-
T1496 usesResource Hijacking MITRE
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
TA0002 uses
-
T1082 usesSystem Information Discovery MITRE
-
T1218.011 usesRundll32 MITRE
-
T1056.001 usesKeylogging MITRE
-
T1070.004 usesFile Deletion MITRE
-
T1105 usesIngress Tool Transfer MITRE
-
T1018 usesRemote System Discovery MITRE
-
T1041 usesExfiltration Over C2 Channel MITRE
-
T1005 usesData from Local System MITRE
-
T1573.001 usesSymmetric Cryptography MITRE
Malware (14)
-
NodeSnakeRAT usesFamily
-
BerserkStealer usesFamily
-
Hotta Killer usesFamily
-
Rhysida usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
SystemBC usesAlienVault Confidence 100
[SystemBC](https://attack.mitre.org/software/S9001) is a malware family offered as a malware-as-a-service (MaaS) that is used to establish command and control and facilitate follow-on activity, including ransomware deployment.[SystemBC](https://attack.mitre.org/software/S9001) executes a variety…
First seen 01/01/1970 · Last seen 16/11/5138 · -
NodeSnake RAT usesFamily
-
Interlock RAT usesFamily
-
Lumma Stealer usesThe MITRE Corporation Confidence 100
[Lumma Stealer](https://attack.mitre.org/software/S1213) is an information stealer malware family in use since at least 2022. [Lumma Stealer](https://attack.mitre.org/software/S1213) is a Malware as a Service (MaaS) where captured data has been…
First seen 01/01/1970 · Last seen 16/11/5138 · -
NodeSnake usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
MintLoader usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
InterlockRAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (9)
-
Public Sector targets
-
Construction targets
-
Manufacturing targets
-
Healthcare targets
-
Finance targets
-
Hospitality targets
-
Government targets
-
Technology targets
-
Education targets
Countries (11)
-
Japan targets
-
Italy targets
-
Virgin Islands, U.S. targets
-
United States of America targets
-
Peru targets
-
Germany targets
-
Australia targets
-
Mexico targets
-
British Indian Ocean Territory targets
-
India targets
-
Canada targets
Indicators (100)
-
doriot.infoindicates -
https://forest-offensive-height-letters.trycloudflare.com/12341234indicates -
71f773b4e9178dcedd402c94fb9384aea6312d8a93f95f3f9dc1249fd4933658indicates -
e69491a61ebc4a9ffc17884063c69a5489a83dd6d71295b4216962a43242a6c8indicates -
2faef6a1a0c00f8d44955c243df3c098f0fccd20c59677d274a43023002a4e90indicates -
sync-time-win.liveindicates -
25a1d86248b7cf5f870dbc9960ce336266473bd40be3a8dcb35e6be88c9df261indicates -
045c041354a6d6b47e91e1124a7dc77397c18e0695ccbc73f87b12a0a1079d46indicates -
settings-win-datamicrosoft.orgindicates -
https://dc-broader-green-norwegian.trycloudflare.com/12341234indicates -
216.245.184.181indicates -
ferrari-rolling-facilities-lounge.trycloudflare.comrelated
Vulnerabilities (CVE) (1)
The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A user-mode process …
- Attack vector
- LOCAL
- Published
- 28/10/2025
- Modified
- 30/01/2026
Organization (11)
-
Swartz Campbell targets
-
Westlake Christian Academy targets
-
Delta Manufacturing targets
-
Hunneman targets
-
RGD Consulting Engineers targets
-
Clarksville ISD targets
-
Apex Spine and Neurosurgery targets
-
Wagon Mound Public Schools targets
-
Elliott-Lewis targets
-
Aero Fabrications targets
-
The Salvation Army targets