← All actors

Interlock

Aliases: Interlock ransomware

Source profile review date: 2026-06-21

Added to the source registry: 2024-10-13 · Source snapshot: 2026-09-15

Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.

Research status: Existing researched dossier

Locally generated translation; linguistic review is still pending.

Executive summary

Interlock has become a rapidly mature ransomware group that combines social engineering, ClickFix/FileFix-like techniques, RATs, cloud tools and multi-platform encryption.

Interlock is very topical due to CISA- warnings, engagement against healthcare and public organisations, Windows/Linux/BSD/ESXi relevance and abuse of legitimate tools such as Cloudflare tunnels and AzCopy.

Latest five known victim claims

Loading stored claims…

    These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.

    Management summary

    Interlock deserves high priority because the group grew from visible ransomware family to mature operational threat in a short time. The actor combines social engineering, remote access, credential theft, data exfiltration and multi-platform impact. That makes Interlock dangerous for organizations with Windows servers, Linux, virtualization, cloud storage and many user interactions.

    The striking point is initial access. Interlock is linked to ClickFix and FileFix-like techniques in public reporting, whereby users are misled to perform command scripts or seemingly legitimate steps. This bypasses classic attachment and macro think images: the user himself performs the first step under social pressure.

    For visitors, the translation is direct: not only block malware, but prevent users from uncontrolled commands, remote tools or scripts. Combine awareness with technical measures: PowerShell logging, application control, browser/download policy, DNS- filtering and detection of RAT- activity.

    Grouping and development

    Interlock became visible around 2024 and grew to a more mature operation in 2025. Public reporting mentions attacks on sectors such as care, government, education and production. CISA warned for increasing activity.

    The group uses double extortion: data is stolen and then it follows encryption or publication printing. Technical width is important: Windows, Linux, BSD and VMware ESXi are listed in analyses as relevant environments or target platforms.

    Interlock is not a static payload. The ecosystem includes social engineering, RATs, cloud tunnels, data exfil and ransomware. That means that detection must run across multiple layers.

    Operation and attack chain

    A Interlock attack can start with social engineering that convinces victims to download software or run command scripts. ClickFix/FileFix-like techniques make users think they're solving a browser, verification or document problem while starting a payload or RAT.

    After initial execution, a Interlock RAT can collect system information, explore Active Directory, search backups and prepare lateral movement. Reporting mentions PHP--based RAT- variants and use of legitimate services for C2 or exfiltration.

    For data diodestal, the actor can use tools like AzCopy or cloud storage routes. Cloudflare tunnels or similar services may make traffic look like legitimer. Detection should therefore look to context: which process starts the connection, which account uses it, what data volume follows?

    The impact phase can touch Windows-, Linux-, BSD- or ESXi environments. Research should explicitly include virtualization, backups, storage and privileged accounts. If ESXi or backup management was in scope, it determines whether recovery can start safely.

    Known IOCs and artifacts

    Artefacts are ClickFix/FileFix-lures, PowerShell- or Run-dialog commands, Interlock RAT- files, PHP--based scripts, Cloudflare tunnel activity, AzCopy usage, data archives, ransom notes and leak site claims.

    Behaviour indicators are sudden PowerShell from user context, download and implement unknown tools, system and AD-enumeration, backup discovery, cloud upload, C2 via legitimate cloud routes and lateral movement to servers.

    Hard IOC pistols must be added per current source. The core of defense is not a single hash, but the stopping of the social engineering chain and making remote access and data transfer visible.

    Victim pattern and lessons

    Public reporting mentions, among other things, care, government and educational environments. Such organisations are vulnerable by many users, complex legacy, sensitive data and high continuity pressure.

    The lesson is that user-driven execution should be taken seriously. If users can paste commands, start unknown tools and run scripts without checking, social engineering can become technical access directly.

    A second lesson is that cloud tools are part of ransomware detection. AzCopy, tunnels and SaaS uploads are legitimate but combined with staging and new accounts highly suspicious.

    How to arm yourself

    Block or restrict ClickFix/FileFix routes. Train users to never paste commands from websites or support chats. Use application control, PowerShell Constrained Language Mode where appropriate and scriptblock logging.

    Detect RAT and tunnel behavior. Cloudflare tunnels, unexpected PHP- processes, AzCopy uploads, new scheduled tasks and unknown remote tools should be correlated.

    Record virtualization and backups in Hunts. Check ESXi, Hyper-V, Veeam, storage management and privileged backup accounts. If these layers are hit, recovery must be validated first.

    Specific Hunts

    Hunt at Interlock very early on user-driven execution. Search for PowerShell, mshta, wscript, randll32, cmd or msiexec that start from browser, explorer or officecontext shortly after a download or web interaction.

    Check ClickFix/FileFix signals: Run-dialog or Explorer address bar abuse, clipboard-like command execution, Base64 PowerShell, download cradle patterns and scripts from Downloads, Temp or AppData.

    Then hunt for RAT- behavior: system information, AD-enumeration, backup discovery, Cloudflare tunnel activity, AzCopy or other cloud transfer, lateral movement to servers and access to ESXi or backup management.

    Exposure and prevention

    Interlock makes it clear that Exposure should also check user behavior and endpoint policy. Can users run scripts themselves, start remote tools or run unknown installers? Then social engineering is a technical risk instantly.

    Check that PowerShell logging, scriptblock logging, AMSI, EDR and application control are really active on workstations and servers. Many organizations have paper policies but exceptions to management workstations.

    Take cloud tools into prevention. AzCopy, rclone and tunnels are legitimate but should not be able to run uncontrolled from normal workstations or servers.

    Sources and uncertainty

    Interlock has stronger public source base than many young groups, including CISA- warnings and multiple technical analyses. Therefore, confidence is high.

    However, the question remains which initial route was used per incident. ClickFix/FileFix is important but does not exclude credials, vulnerable services or supplier routes.

    Label in updates always whether an observation is part of social engineering, RAT, exfiltration, encryption or virtualization impact. That makes the file useful for Hunts.

    Executive Scenario and SOC

    A Interlock scenario often starts with a user who thinks he is doing a legitimate act, using instructions that look like support, verification or troubleshooting, which makes the first step not feel like phishing.

    The SOC must highly value browser-to-command execution. If a web interaction is followed by PowerShell, msiexec, randll32 or an unknown remote tool, that is a critical chain.

    For the board, Interlock is an example that awareness and technology have to work together. A warning helps employees, but without application control and logging the attack remains feasible.

    What the visitor needs to check out in concrete terms

    Check that users can paste and execute commands without restrictions. Limit PowerShell, block execution from user directories and log scriptblocks centrally.

    Check that remote tools are allowed on the basis of allowlist. Unknown support tools, tunnels and portable executables should not be able to start without permission.

    Check virtualization layer and backups explicitly. Interlock relevance for Linux/BSD/ESXi means that Windows-only logging is insufficient.

    Relationship with Amuneth Exposure

    Exposure can support Interlock risk by making vulnerable web and download routes visible, but also by explaining why user interaction is an attack plane.

    Scans for CMS, Laravel, WordPress and Drupal are indirectly relevant here: a compromised website can be used as a lure, payload host or credential source.

    Reporting should therefore clarify what findings make phishing, payload hosting or deception easier, making prevention more concrete for customers.

    Additional Defence Notes

    Interlock should be made concrete in awareness material. Not only do you not say "click" on phishing . Show examples of websites that ask users to paste a command or to fix a problem manually. That is the form employees need to recognize.

    Technically, the organization has to assume that someone is making a mistake. Therefore, blocking measures are needed: execution control, script restrictions, limited local rights and logging that stands out within minutes.

    A Interlock exercise should also touch Linux, BSD, ESXi and backup platforms. If only Windows-endpoints are tested, a significant part of the threat remains out of the picture.

    Indicators of compromise (IOCs)

    Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.

    TypeValueSourceContext
    techniqueClickFix/FileFix-style social engineering executionCISA / Forescout / public reportingMisdirection to let users run commands themselves.
    toolingInterlock RAT and PHP-based RAT variantspublic Interlock analysisPost-exploitation and discovery.
    toolingCloudflare tunnels and AzCopy-like cloud transferForescout / public reportingC2 and exfiltration can be done through legitimate services.

    Sources

    Evidence and limitations

    Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.