interlock
· Published 20/12/2025 08:54 · Modified 13/03/2026 10:45
· Source: Ransomware.Live
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 08:54
- Modified
- 13/03/2026 10:45
- Updated at
- 13/03/2026 10:45
- Revoked
- No
- Author / Source
- Ransomware.Live
- Resource level
- —
- Primary motivation
- —
- Related entities
- 8 reports, 61 attack patterns (mitre), 14 malware, 9 sectors, 11 countries, 100 indicators, 1 vulnerabilities (cve), 11 organization
Description
No description available
Marking (TLP)
TLP:CLEAR
Labels
ransomware
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (8)
-
1 CVE 10 MITREs 4 Malwares 8 Observables 1 APT
-
7 MITREs 1 Malware 1 APT
-
11 MITREs 4 Malwares 24 Observables 1 APT
-
16 MITREs 2 Malwares 12 Observables 1 APT
-
11 MITREs 4 Malwares 1 APT
-
5 MITREs 1 Malware 1 APT
-
11 MITREs 1 Malware 5 Observables 1 APT
-
15 MITREs 2 Malwares 2 Observables 1 APT
Attack patterns (MITRE) (61)
-
T1204.002 usesMalicious File MITRE
-
T1112 usesModify Registry MITRE
-
T1571 usesNon-Standard Port MITRE
-
T1485 usesData Destruction MITRE
-
T1027 usesObfuscated Files or Information MITRE
-
T1059.007 usesJavaScript MITRE
-
T1055 usesProcess Injection MITRE
-
T1059.003 usesWindows Command Shell MITRE
-
T1518 usesSoftware Discovery MITRE
-
T1048 usesExfiltration Over Alternative Protocol MITRE
-
T1486 usesData Encrypted for Impact MITRE
-
T1210 usesExploitation of Remote Services MITRE
Malware (14)
-
Interlock usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Interlock Ransomware usesFamily
Sectors (9)
-
Public Sector targets
-
Construction targets
-
Manufacturing targets
-
Healthcare targets
-
Finance targets
-
Hospitality targets
-
Government targets
-
Technology targets
-
Education targets
Countries (11)
-
Japan targets
-
Italy targets
-
Virgin Islands, U.S. targets
-
United States of America targets
-
Peru targets
-
Germany targets
-
Australia targets
-
Mexico targets
-
British Indian Ocean Territory targets
-
India targets
-
Canada targets
Indicators (100)
-
e307d3e9b8de59311c692b2ab0ee864f0d469066e041141d577b65b43a4b3ffaindicates -
45.61.136.109indicates -
2mail.coindicates -
0fff8fb05cee8dc4a4f7a8f23fa2d67571f360a3025b6d515f9ef37dfdb4e2eaindicates -
views-ethics-orientation-roommate.trycloudflare.comindicates -
santa-reflection-capitol-classifieds.trycloudflare.comindicates -
spa-step-hopkins-islands.trycloudflare.comindicates -
3e4407dfd827714a66e25c2baccefd915233eeec8fb093257e458f4153778beeindicates -
https://album-anthony-rn-submission.trycloudflare.com/25423565indicates -
eb1cdf3118271d754cf0a1777652f83c3d11dc1f9a2b51e81e37602c43b47692indicates -
https://airbluefootgear.com/wp-includes/images/xits.phpindicates -
securities-variance-vocal-temporal.trycloudflare.comindicates
Vulnerabilities (CVE) (1)
CVE-2025-61155
targets
5.5
Medium
The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A user-mode process …
- Attack vector
- LOCAL
- Published
- 28/10/2025
- Modified
- 30/01/2026
Organization (11)
-
Swartz Campbell targets
-
Westlake Christian Academy targets
-
Delta Manufacturing targets
-
Hunneman targets
-
RGD Consulting Engineers targets
-
Clarksville ISD targets
-
Apex Spine and Neurosurgery targets
-
Wagon Mound Public Schools targets
-
Elliott-Lewis targets
-
Aero Fabrications targets
-
The Salvation Army targets