216.73.217.22

Interlock ransomware evolving under the radar

· Published 16/04/2025 14:00 · Modified 16/04/2025 14:51

Export JSON

Essential information

Published
16/04/2025 14:00
Modified
16/04/2025 14:51
Tags
2025-04-16 berserkstealer clickfix credential-stealer double-extortion fake updaters interlock ransomware interlock rat lumma powershell backdoor ransomware remote access trojan
Related entities
1 intrusion sets (apt), 11 techniques (mitre), 4 malware

Description

The group, active since September 2024, has shown adaptability and innovation in its tactics despite a relatively low victim count. They employ fake browser updates and the technique for initial access, followed by a multi-stage attack chain involving PowerShell backdoors, credential stealers, and a custom . The group targets various sectors across North America and Europe, conducting Big Game Hunting and double extortion campaigns. Interlock has been observed improving their tools, including evolving their and modifying their ransom notes to emphasize legal repercussions. The group's focus on maintaining relevance while avoiding large-scale visibility suggests a strategic approach to their operations.

External references