Interlock is a double-extortion ransomware operation active since at least late 2024. It steals data prior to encryption and pressures victims through a Tor-based leak site and regulatory-themed extortion messaging. Victims have included organizations in healthcare, education, government, manufacturing, engineering, construction, and other critical-infrastructure and enterprise environments across North America and Europe.
Interlock has operated across Windows and virtualization environments including VMware ESXi, and reporting also links it to Linux and FreeBSD/ESXi encryptors. The ransomware family has been associated with a broader intrusion toolkit that includes custom remote-access trojans, credential-harvesting components, reconnaissance scripts, proxying infrastructure, and alternate remote-access software. Observed custom implants include NodeSnake and InterlockRAT, which provide persistent command execution, file transfer, proxying, and redundant access paths.
A recurring initial-access pattern is ClickFix-style social engineering in which a fake CAPTCHA or fake update prompt convinces a user to paste and run a malicious command in Windows. Interlock has also been observed exploiting CVE-2026-20131, a critical Cisco Secure Firewall Management Center remote-code-execution vulnerability, as a zero-day for initial access to enterprise edge infrastructure. After foothold establishment, the group conducts extensive reconnaissance, harvests credentials, moves laterally, tampers with security tooling, and stages data for exfiltration before deploying ransomware.
Observed post-compromise tradecraft includes memory acquisition and credential extraction using legitimate forensic tools, Kerberoasting, NTLM downgrade abuse, scheduled-task persistence, creation of privileged accounts, use of remote administration software for persistence, and deployment of reverse-proxy infrastructure and memory-resident backdoors for evasion and resilience. Interlock activity has also resulted in disruption of hypervisors and broader enterprise operations, consistent with mature multi-stage ransomware intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Amazon reported that the Interlock ransomware group has been exploiting the maximum severity vulnerability, CVE-2026-20131... The server hosting the binary was used to distribute malware belonging to the Interlock family.
PrintNightmare exploit (Interlock staging)
Local privilege escalation exploit CVE-2023-36036 (JunkFiction-crypted) ... CVE CVE-2023-36036 Local privilege escalation exploit used by Interlock and ModeloRAT operators
Interlock ... concealed ... through the custom Hotta Killer evasion tool, which harnesses a zero-day flaw in the legitimate gaming anti-cheat driver GameDriverx64.sys, tracked as CVE-2025-61155, as part of a Bring Your Own Vulnerable Driver attack. ... kernel termination of security software prior to encryption activities.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Amazon reported that the Interlock ransomware group has been exploiting the maximum severity vulnerability, CVE-2026-20131... The server hosting the binary was used to distribute malware belonging to the Interlock family.
Interlock ransomware is taking a familiar Windows security tool and using it for credential theft.
The Rhysida and Interlock groups, which are known to attack healthcare and other critical infrastructure, have similar TTPs and encryption binaries, leading to some speculation of a connection between the two groups.
The e-crime group is primarily associated with a wide range of malicious tools, including NodeSnake, Interlock RAT, JunkFiction loader, and Interlock ransomware.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
The agencies said they are aware of Interlock encryptors designed for Windows and Linux operating systems and have observed cyber actors obtaining access using an uncommon method of drive-by download from compromised legitimate websites, among other tactics.
Amazon threat intelligence has identified an active Interlock ransomware campaign exploiting CVE-2026-20131, a critical vulnerability in Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device
The Java variant adds two features... The UpdateThread creates a self-deleting scheduled task... Like the Java variant, the PE uses self-deleting scheduled tasks... A daily scheduled task runs the ransomware at 20:00 as SYSTEM.
A PowerShell-based reconnaissance script systematically collects detailed system and network information, including installed software, running services, browser data, and active connections.
The campaign centers around a flaw affecting Cisco Secure Firewall Management Center (FMC) software... It allows an unauthenticated remote attacker to execute arbitrary Java code with root privileges on affected FMC devices... Interlock had already begun exploiting this flaw as early as January 26, 2026.
The Java variant adds two features... The UpdateThread creates a self-deleting scheduled task... Like the Java variant, the PE uses self-deleting scheduled tasks... A daily scheduled task runs the ransomware at 20:00 as SYSTEM.
The Java variant adds two features... The UpdateThread creates a self-deleting scheduled task... Like the Java variant, the PE uses self-deleting scheduled tasks... A daily scheduled task runs the ransomware at 20:00 as SYSTEM.
“Interlock ransomware deploys “Hotta Killer” exploiting ... driver zero-day (CVE-2025-61155) to disable EDR/AV...”
The Windows variant imports wevtapi.dll and calls EvtClearLog to wipe Windows event logs. This is the only variant in the toolkit that clears event logs.
DELETE 0x0c fs.rmSync(__filename)... If the counter passes 40, the implant deletes itself... self-deleting scheduled task... --delete (self-delete after encryption)
A PowerShell-based reconnaissance script systematically collects detailed system and network information... and active connections.
One variant, written in JavaScript... establish[es] encrypted communication with command-and-control servers via WebSockets.
Interlock employs a Bash script that converts compromised Linux servers into HTTP reverse proxies. These proxies forward traffic to attacker-controlled systems while erasing logs every five minutes.
This triggered the next phase of the attack, where Interlock issued commands to download and execute a malicious Linux binary.
Such activity is significant as it often indicates ransomware behavior, where files are encrypted and the originals are deleted.
70 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
60 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Interlock is discussed in the context of an ESXi decryptor, indicating ransomware tooling used to decrypt files after payment and revealing details about how the corresponding encryptor works.
A ransomware family/group associated with publishing stolen employee data after payment demands were refused.
Ransomware family/group mentioned as responsible for several attacks against the education sector in the period discussed.
Ransomware that combines data theft with encryption and extortion. In this intrusion it used ClickFix-based initial access, abused legitimate memory forensics tools to extract NTLM/LM hashes and account data, moved laterally to a domain controller, tampered with security tools, stole data, and ultimately deployed a ransomware payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.