216.73.216.36

Interlock Ransomware Targeting Businesses

· Published 29/08/2025 20:20 · Modified 01/09/2025 08:32

Export JSON

Essential information

Published
29/08/2025 20:20
Modified
01/09/2025 08:32
Tags
2025-08-29 aes-256-gcm code obfuscation data theft europe file-encryption interlock north america openssl ransomware rsa-4096
Related entities
1 intrusion sets (apt), 7 techniques (mitre), 1 malware, 1 others

Description

The group has been actively targeting businesses and critical infrastructures in and since September 2024. Their employs encryption with key protection, leveraging the library for efficient file encryption. The malware includes techniques and specific arguments for various behaviors. It excludes certain folders, file extensions, and files from encryption to avoid system damage. The changes file extensions to '.!NT3RLOCK' and may terminate processes during encryption. 's operations involve and public disclosure threats for ransom leverage. The group utilizes a Tor-based negotiation site and references legal regulations to pressure victims. To counter this threat, offsite data backups and regular recovery drills are recommended.

External references