216.73.217.22

Unwrapping the emerging Interlock ransomware attack

· Published 07/11/2024 16:41 · Modified 07/11/2024 21:07

Export JSON

Essential information

Published
07/11/2024 16:41
Modified
07/11/2024 21:07
Tags
2024-11-07 azure credential-stealer double-extortion interlock keylogger ransomware rat rdp rhysida
Related entities
2 observables, 1 intrusion sets (apt), 15 techniques (mitre), 2 malware, 5 others

Description

A new group called has emerged, targeting various sectors with big-game hunting and double extortion attacks. The group uses a sophisticated delivery chain including a disguised as a browser updater, PowerShell scripts, credential stealers, and keyloggers. They primarily move laterally through and exfiltrate data using Storage Explorer. The encrypts files with the . extension and drops ransom notes. The attackers claim to exploit unaddressed vulnerabilities and justify their actions as holding companies accountable for poor cybersecurity. Analysis suggests possible links to the group based on similarities in tactics and code. The attack timeline indicates a dwell time of about 17 days in the victim's environment.

External references