interlock
· Published 20/12/2025 08:54 · Modified 13/03/2026 10:45
· Source: Ransomware.Live
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 08:54
- Modified
- 13/03/2026 10:45
- Updated at
- 13/03/2026 10:45
- Revoked
- No
- Author / Source
- Ransomware.Live
- Resource level
- —
- Primary motivation
- —
- Related entities
- 8 reports, 61 attack patterns (mitre), 14 malware, 9 sectors, 11 countries, 100 indicators, 1 vulnerabilities (cve), 11 organization
Description
No description available
Marking (TLP)
TLP:CLEAR
Labels
ransomware
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (8)
-
1 CVE 10 MITREs 4 Malwares 8 Observables 1 APT
-
7 MITREs 1 Malware 1 APT
-
11 MITREs 4 Malwares 24 Observables 1 APT
-
16 MITREs 2 Malwares 12 Observables 1 APT
-
11 MITREs 4 Malwares 1 APT
-
5 MITREs 1 Malware 1 APT
-
11 MITREs 1 Malware 5 Observables 1 APT
-
15 MITREs 2 Malwares 2 Observables 1 APT
Attack patterns (MITRE) (61)
-
T1204.002 usesMalicious File MITRE
-
T1112 usesModify Registry MITRE
-
T1571 usesNon-Standard Port MITRE
-
T1485 usesData Destruction MITRE
-
T1027 usesObfuscated Files or Information MITRE
-
T1059.007 usesJavaScript MITRE
-
T1055 usesProcess Injection MITRE
-
T1059.003 usesWindows Command Shell MITRE
-
T1518 usesSoftware Discovery MITRE
-
T1048 usesExfiltration Over Alternative Protocol MITRE
-
T1486 usesData Encrypted for Impact MITRE
-
T1210 usesExploitation of Remote Services MITRE
Malware (14)
-
NodeSnakeRAT usesFamily
-
BerserkStealer usesFamily
-
Hotta Killer usesFamily
-
Rhysida usesFamily
-
SystemBC usesAlienVault Confidence 100
[SystemBC](https://attack.mitre.org/software/S9001) is a malware family offered as a malware-as-a-service (MaaS) that is used to establish command and control and facilitate follow-on activity, including ransomware deployment.[SystemBC](https://attack.mitre.org/software/S9001) executes a variety…
First seen 01/01/1970 · Last seen 16/11/5138 · -
NodeSnake RAT usesFamily
-
Interlock RAT usesFamily
-
Lumma Stealer usesFamily
-
NodeSnake usesFamily
-
MintLoader usesFamily
-
InterlockRAT usesFamily
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (9)
-
Public Sector targets
-
Construction targets
-
Manufacturing targets
-
Healthcare targets
-
Finance targets
-
Hospitality targets
-
Government targets
-
Technology targets
-
Education targets
Countries (11)
-
Japan targets
-
Italy targets
-
Virgin Islands, U.S. targets
-
United States of America targets
-
Peru targets
-
Germany targets
-
Australia targets
-
Mexico targets
-
British Indian Ocean Territory targets
-
India targets
-
Canada targets
Indicators (100)
-
basiclock.ccindicates -
1105a3050e6c842fb9411d4f21fd6fdb119861c15f7743e244180a4e64b19b83indicates -
e9ff4d40aeec2ff9d2886c7e7aea7634d8997a14ca3740645fd3101808cc187bindicates -
61d092e5c7c8200377a8bd9c10288c2766186a11153dcaa04ae9d1200db7b1c5indicates -
ecologilives.comindicates -
periodic-priest-games-assessed.trycloudflare.comindicates -
nedy-throwing-knock-whats.trycloudflare.comindicates -
stix 100/100 Revoked· Valid until 25/01/2026 · Source: AlienVault
-
www.sublime-forecasts-pale-scored.trycloudflare.comindicates -
351b8a0081fd9f5c35497f5183fb14aef73c1af75628ae689c9218689db01cd9indicates -
4672fe8b37b71be834825a2477d956e0f76f7d2016c194f1538139d21703fd6eindicates -
https://lcd-add-palace-switching.trycloudflare.com/12341234indicates
Vulnerabilities (CVE) (1)
CVE-2025-61155
targets
5.5
Medium
The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A user-mode process …
- Attack vector
- LOCAL
- Published
- 28/10/2025
- Modified
- 30/01/2026
Organization (11)
-
Swartz Campbell targets
-
Westlake Christian Academy targets
-
Delta Manufacturing targets
-
Hunneman targets
-
RGD Consulting Engineers targets
-
Clarksville ISD targets
-
Apex Spine and Neurosurgery targets
-
Wagon Mound Public Schools targets
-
Elliott-Lewis targets
-
Aero Fabrications targets
-
The Salvation Army targets