The FBI, Cybersecurity and Infrastructure Security Agency, Department of Health and Human Services, and Multi-State Information Sharing and Analysis Center July 22 released a joint advisory detailing malicious activity from Interlock ransomware. Activity was first discovered in September 2024 and as recently as June, targeting various organizations and critical infrastructure. The agencies said they are aware of Interlock encryptors designed for Windows and Linux operating systems and have observed cyber actors obtaining access using an uncommon method of drive-by download from compromised legitimate websites, among other tactics. The advisory includes mitigation strategies to help protect against the ransomware.

“Interlock has been directly implicated in high impact ransomware attacks against hospitals and health systems, resulting in the disruption to care delivery and creating a risk to patient and community safety,” said John Riggi, AHA national advisor for cybersecurity and risk. “It remains one of the top ransomware groups targeting health care. Health care organizations are encouraged to pay special attention to this alert, implement the recommended mitigation protocols and load the detailed indicators of compromise into network defenses.” 

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity
 

Headline
The White House issued an executive order March 6 to combat cybercrimes by threat groups. The order highlights how such groups can receive willing or…
Headline
The Administration for Strategic Preparedness and Response has released a new cybersecurity module for organizations to conduct risk assessments. The free…
Perspective
Public
As the world has learned in recent years, today’s conflicts are fought with many weapons, and cyber warfare is an integral part of the arsenal.As of this…
Headline
The FBI is reminding critical infrastructure organizations to implement mitigations from a June 2025 fact sheet on potential actions by Iranian-affiliated…
Headline
The Cybersecurity and Infrastructure Security Agency Feb. 26 released a report that updates findings from last year on RESURGE malware used to gain covert…
Headline
U.S. and international agencies Feb. 25 released guidance on protecting Cisco Software-defined Wide-area Networking systems from exploitation by malicious…