Interlock is a financially motivated ransomware and data-extortion threat actor active by at least 2024 and prominently observed through 2025 and 2026. The group conducts double-extortion operations, combining network intrusion and data theft with ransomware deployment or the threat of public disclosure through a leak site when victims refuse to pay. Reported victims span healthcare, education, government, manufacturing, nonprofit, logistics, and community-service organizations in multiple countries, including the United States, Canada, the United Kingdom, and Australia. Interlock has been associated with opportunistic enterprise targeting rather than a narrowly defined vertical focus, although healthcare, education, and public-sector entities appear repeatedly among known victims. Publicly reported victimology includes municipal government, schools, clinics, treatment providers, dental and hearing-care organizations, manufacturers, and regional service providers. In several cases, the group publicly claimed large-scale exfiltration of sensitive personal, medical, financial, operational, and internal business records and used those claims to pressure victims. Interlock’s intrusion tradecraft has been linked to ClickFix-style social engineering for initial access, in which users are manipulated into executing attacker-supplied commands. Reporting indicates the group has relied on this style of access for an extended period and that related campaigns were still active in 2026. Interlock activity has also been tied to the NodeSnake remote access trojan, including renewed deployments delivered through ClickFix-style lures. Observed NodeSnake development included screenshot-collection capability and metadata suggestive of affiliate tracking, consistent with an evolving criminal operation. The group has also been linked through shared infrastructure or upstream access relationships to the KongTuke initial access broker, also known as Woodgnat. That broker has been publicly associated with social-engineering-driven access operations and malware such as ModeloRAT and Mistic, and has been linked to multiple ransomware ecosystems including Interlock. These links suggest Interlock may at times obtain footholds through third-party access brokers or affiliates rather than exclusively through its own direct intrusion activity. Known aliases include interlock, interlock_group, interlock_ransomware, and interlock_ransomware_group. Interlock is best understood as a cybercriminal ransomware operation rather than a nation-state actor. No high-confidence public attribution to a specific government is established in the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
CVE CVE-2026-20131 Network edge device vulnerability exploited by Interlock for initial access
Hotta Killer (Interlock): exploits a gaming anti-cheat driver zero-day (CVE-2025-61155) to attack FortiEDR
Local privilege escalation exploit CVE-2023-36036 (JunkFiction-crypted) ... CVE CVE-2023-36036 Local privilege escalation exploit used by Interlock and ModeloRAT operators
83 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack and associated data breach against Paragon Store Fixtures, resulting in exposure of contracts, architectural plans, confidential design documentation, and client-related intellectual property.
Conducting a ransomware attack and data extortion against Centre for Newcomers, claiming theft of 380 GB of personal client data, financial information, and HR planning/policy data.
Conducting a ransomware attack and associated data breach against Converting Equipment International, with claims of leaking confidential business, subsidiary, and financial information.
Claimed responsibility for the Naper Grove Vision Care attack and theft of patient data in a ransomware-linked intrusion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.