H-ISAC TLP White: Threat Actor Profile: Interlock Ransomware
Executive Summary
Interlock Ransomware is an opportunistic, financially motivated threat actor that emerged in late 2024. Operating as a closed group rather than a Ransomware-as-a-Service (RaaS) model, Interlock employs a double-extortion strategy—exfiltrating sensitive data and encrypting systems, then threatening their target/victims to leak the stolen data on their Tor-based Worldwide Secrets Blog if a ransom is not paid.
They are particularly notable for utilizing atypical initial access vectors for ransomware groups, such as drive-by downloads and the ClickFix social engineering technique, which tricks users into manually executing malicious scripts.
View the detailed report below.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact: