interlock
· Published 20/12/2025 08:54 · Modified 13/03/2026 10:45
· Source: Ransomware.Live
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 08:54
- Modified
- 13/03/2026 10:45
- Updated at
- 13/03/2026 10:45
- Revoked
- No
- Author / Source
- Ransomware.Live
- Resource level
- —
- Primary motivation
- —
- Related entities
- 8 reports, 61 attack patterns (mitre), 14 malware, 9 sectors, 11 countries, 100 indicators, 1 vulnerabilities (cve), 11 organization
Description
No description available
Marking (TLP)
TLP:CLEAR
Labels
ransomware
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (8)
-
1 CVE 10 MITREs 4 Malwares 8 Observables 1 APT
-
7 MITREs 1 Malware 1 APT
-
11 MITREs 4 Malwares 24 Observables 1 APT
-
16 MITREs 2 Malwares 12 Observables 1 APT
-
11 MITREs 4 Malwares 1 APT
-
5 MITREs 1 Malware 1 APT
-
11 MITREs 1 Malware 5 Observables 1 APT
-
15 MITREs 2 Malwares 2 Observables 1 APT
Attack patterns (MITRE) (61)
Malware (14)
-
NodeSnakeRAT usesFamily
-
BerserkStealer usesFamily
-
Hotta Killer usesFamily
-
Rhysida usesFamily
-
SystemBC usesFamily
-
NodeSnake RAT usesFamily
-
Interlock RAT usesFamily
-
Lumma Stealer usesFamily
-
NodeSnake usesFamily
-
MintLoader usesFamily
-
InterlockRAT usesFamily
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (9)
-
Public Sector targets
-
Construction targets
-
Manufacturing targets
-
Healthcare targets
-
Finance targets
-
Hospitality targets
-
Government targets
-
Technology targets
-
Education targets
Countries (11)
-
Japan targets
-
Italy targets
-
Virgin Islands, U.S. targets
-
United States of America targets
-
Peru targets
-
Germany targets
-
Australia targets
-
Mexico targets
-
British Indian Ocean Territory targets
-
India targets
-
Canada targets
Indicators (100)
-
open-exceptions-cleared-feelings.trycloudflare.comindicates -
forest-offensive-height-letters.trycloudflare.comindicates -
a5623b6a6f289bb328e4007385bdb1659407a9e825990a0faaef3625a2e782cfindicates -
5cbc2ae758043bb58664c28f32136e9cada50a8dc36c69670ddef0a3ef6757d8indicates -
b36c20c757c4780f89272ce224a29a5a61b62733367893574196debde19383feindicates -
nettixx.comindicates -
cf1-winows-ww.comindicates -
a26f0a2da63a838161a7d335aaa5e4b314a232acc15dcabdb6f6dbec63cda642indicates -
0e0a647b3156d430cd70ad5a430277dc99014d069940a64d9db1ecd60ca00467indicates -
playiro.netindicates -
05c99f2c1a218ce4a985fd03a3a510c2eaf08ef4772f93ef4f2d5da6cd9b86a1indicates -
suffering-arnold-satisfaction-prior.trycloudflare.comindicates
Vulnerabilities (CVE) (1)
CVE-2025-61155
targets
5.5
Medium
The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A user-mode process …
- Attack vector
- LOCAL
- Published
- 28/10/2025
- Modified
- 30/01/2026
Organization (11)
-
Swartz Campbell targets
-
Westlake Christian Academy targets
-
Delta Manufacturing targets
-
Hunneman targets
-
RGD Consulting Engineers targets
-
Clarksville ISD targets
-
Apex Spine and Neurosurgery targets
-
Wagon Mound Public Schools targets
-
Elliott-Lewis targets
-
Aero Fabrications targets
-
The Salvation Army targets