Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Interlock

129
Global rank
105 infographic chevron month
Month rank
105 infographic chevron week
Week rank
0
IOCs

Interlock is a relatively recent entrant into the ransomware landscape. First identified in 2023, it's a multi-functional malware strain used in ransomware-as-a-service (RaaS) operations.

Ransomware
Type
Unknown
Origin
1 October, 2023
First seen
23 April, 2025
Last seen

How to analyze Interlock with ANY.RUN

Type
Unknown
Origin
1 October, 2023
First seen
23 April, 2025
Last seen

IOCs

IP addresses
140.82.14.117
45.61.136.202
84.200.24.41
45.61.136.228
188.34.195.44
168.119.96.41
23.227.203.162
96.62.214.11
5.252.177.228
64.94.84.85
65.38.120.47
80.87.206.189
216.245.184.181
65.109.226.176
49.12.102.206
193.149.180.158
177.136.225.153
49.12.69.80
212.237.217.182
85.239.52.252
Domains
washing-cartridges-watts-flags.trycloudflare.com
suffering-arnold-satisfaction-prior.trycloudflare.com
ecologilives.com
casting-advisors-older-invitations.trycloudflare.com
apple-online.shop
microstteams.com
analytical-russell-cincinnati-settings.trycloudflare.com
una-idol-ta-missile.trycloudflare.com
forest-offensive-height-letters.trycloudflare.com
microsoft-msteams.com
investigators-boxing-trademark-threatened.trycloudflare.com
open-exceptions-cleared-feelings.trycloudflare.com
complement-parliamentary-chairs-hc.trycloudflare.com
fotos-phillips-princess-baker.trycloudflare.com
refrigerator-cheers-indicator-ferrari.trycloudflare.com
speak-head-somebody-stays.trycloudflare.com
mortgage-i-concrete-origins.trycloudflare.com
photo-auction-visual-gains.trycloudflare.com
advanceipscaner.com
sublime-forecasts-pale-scored.trycloudflare.com
Last Seen at

Recent blog posts

post image
How Threat Intelligence Feeds Help During Inc...
watchers 679
comments 0
post image
PE32 Ransomware: A New Telegram-Based Threat...
watchers 3486
comments 0
post image
Seamlessly Integrate ANY.RUN’s Services into...
watchers 532
comments 0

What is Interlock malware?

Interlock is a modular ransomware tool that enables hackers to lock and encrypt files, exfiltrate data, and demand ransoms in double extortion schemes. It targets both Windows and Linux systems, with 64-bit executables (Windows PE and Linux ELF formats).

Interlock gained attention for its stealth and customizability, starting from targeting small and midsize enterprises with limited cybersecurity maturity and proceeding to industry leaders for really big ransoms. Healthcare organizations are another common victim of Interlock.

Discover detailed investigation into Interlock attacks on U.S. hospitals and healthcare providers.

Like many modern malware strains, Interlock leverages common but effective attack vectors. Adversaries send malicious attachments or links in well-crafted spear phishing messages, sometimes including QR codes or cloud-sharing links to bypass email filters. They exploit vulnerabilities, purchase credentials from initial access brokers and employ malvertising — drive-by downloads from fake ads or compromised legitimate websites.

Upon a successful infiltration, Interlock exploits active directory misconfigurations and uses PowerShell, WMI, and RDP for lateral movement within the network. Having established itself in the system, it dumps credentials from memory, exfiltrates data before encryption (double extortion), encrypts data with strong algorithms (often AES or ChaCha20) and greets the victim with a customized ransom note. Optionally, Interlock can recruit keyloggers, browser data collectors, and screenshot capturing.

The malware affects both Windows and Linux environments, with binaries tailored for each, indicating broad compatibility and intent to hit diverse infrastructures. It may use scheduled tasks or registry modifications to maintain access, ensuring it can resume operations after a reboot.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Interlock Ransomware’s Prominent Features

Interlock poses significant risks due to its:

  • Sector Impact: Healthcare and government sectors are particularly vulnerable due to their reliance on uptime and data confidentiality. Disruptions can lead to life-threatening delays or exposure of classified information.
  • Big-Game Hunting: Interlock targets high-value organizations, demanding large ransoms, but can also cripple smaller entities or those with limited cybersecurity budgets.
  • Broad Targeting: Its ability to hit both Windows and Linux systems makes it a threat to diverse environments, from enterprise servers to critical infrastructure.
  • Double-Extortion Strategy: The threat of data leaks amplifies financial and reputational damage, especially for organizations handling sensitive data.
  • Persistence: Its ability to maintain access increases the risk of repeated attacks or secondary payloads.

Interlock is notable for deploying a rare FreeBSD encryptor, aiming at critical infrastructure servers (e.g., web hosting, mail servers). While specific FreeBSD attacks are not yet detailed, this capability suggests potential for broader disruption in future incidents.

Interlock’s Execution Process and Technical Details

To watch Interlock enforce its varying attack scenarios, search for this malware via ANY.RUN’s Threat Intelligence Lookup and explore the analyses of its samples publicly submitted in the Interactive Sandbox.

threatName:"interlock"

Interlock ransomware samples in ANY.RUN Sandbox Interlock ransomware analyses in ANY.RUN's Interactive Sandbox

Let’s watch one of the analysis sessions closer

The execution chain of Interlock ransomware unfolds in several stages, employing both deception and sophisticated tools to compromise and extort victims. It typically begins with a drive-by compromise, where users are tricked into visiting phishing websites that appear legitimate. These sites offer fake updates or tools, which, once downloaded, infect the user’s device with malware. For example, malicious software might be disguised as a legitimate update for a popular application such as Chrome or Microsoft Edge. In one observed instance, the executable file was named upd_9488679.exe, where upd is short for “update,” although it can also appear under names like Update or ChromeSetup.

Once inside the system, attackers may deploy malicious payloads or execute harmful commands to take full control of the victim’s network. Prior to encryption, they often exfiltrate sensitive data as part of a double extortion strategy, threatening not only to encrypt the data but also to release the stolen information publicly if the ransom is not paid.

Next, the Interlock ransomware encryptor is deployed, appending the .interlock extension to files and dropping a ransom note titled !README!.txt in affected directories. This note typically provides instructions on how to contact the attackers and pay the ransom. The reliance on double extortion further pressures victims, who risk losing both access to their data and control over the disclosure of sensitive information.

Following its main functions, the ransomware may erase Windows event logs to conceal evidence of its activities. It can also delete its own binary after encryption, further complicating forensic analysis and recovery efforts.

Interlock ransomware analysis in ANY.RUN A sample of Interlock detonated inside ANY.RUN's Interactive Sandbox

What are the examples of the best-known Interlock attacks?

  • Wayne County, a government entity in Michigan, was hit by Interlock in early October 2024. The breach disrupted local government operations, potentially affecting public services. Interlock demanded a ransom, reportedly ranging from hundreds of thousands to millions of dollars, though it’s unclear if the ransom was paid.
  • Brockton Neighborhood Health Center was breached by Interlock, with the attack going undetected until December 17, 2024. Attackers used a fake Google Chrome updater to gain initial access, deploying a remote access tool (RAT) to exfiltrate sensitive patient data and encrypt files. The delayed detection allowed Interlock to maintain persistence for nearly two months.
  • Interlock claimed responsibility for attacking Andretti Indoor Karting & Games — a U.S. entertainment chain — in March 2025, alleging they stole 1.2 TB of data, including W-9 forms, financial records, and passports. The attack led to a temporary closure of multiple locations. This attack showed Interlock’s willingness to target non-critical sectors like entertainment, broadening their victim pool.

Gathering Threat Intelligence on Interlock malware

Integrating threat intelligence into security operations is much more efficient than paying huge ransoms to Interlock operators or dealing with devastating aftermath of data loss and leaks. Focus on TTPs (tactics, techniques, procedures) shared by TI reports, such as phishing, scheduled tasks to anticipate attack vectors.

Leverage ANY.RUN’s Threat Intelligence Lookup to hunt for IOCs specific to Interlock, like domains, IPs, or file hashes.

Each analysis session in the Sandbox contains a number of IOCs. Use them as search requests to TI Lookup for further exploring the threat and gathering data for monitoring and detection.

Interlock malicious files Files found in an Interlock sample during Sandbox analysis

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Interlock is a young ransomware market player yet already notorious for its big ransom appetites, opportunistic targeting across various sectors, and sophisticated tactics to infiltrate systems, exfiltrate data, and disrupt operations. The group's activities have had significant impacts on the affected organizations, leading to operational downtime, data breaches, and potential financial losses.

To avoid becoming the next victim, reinforce your proactive cybersecurity efforts with actionable data brough to you by threat intelligence.

Start with 50 requests in TI Lookup to collect IOCs on Interlock and be ready to detect and respond

HAVE A LOOK AT

Bluesky Ransomware screenshot
BlueSky ransomware, first identified in June 2022, shares code similarities with other well-known ransomware families like Conti and Babuk. It primarily spreads via phishing emails and malicious links and can propagate through networks using SMB protocols. BlueSky uses advanced evasion techniques, such as hiding its processes from debuggers via the NtSetInformationThread API, making it difficult for analysts to detect and mitigate its attacks.
Read More
LockBit screenshot
LockBit
lockbit
LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations.
Read More
Black Basta screenshot
Black Basta
blackbasta
Black Basta is a ransomware-as-a-service operated by Storm-1811. It emerged in 2022 and uses double extortion tactics, encrypting data and stealing it for ransom. The malware often gains access through spear-phishing and uses tools like QakBot and Cobalt Strike. It's known for exploiting system vulnerabilities and using advanced obfuscation techniques.
Read More
Razr screenshot
Razr
razr
Razr is a destructive ransomware that infiltrates systems to encrypt files, rendering them inaccessible to users. It appends the ".razr" extension to the encrypted files and drops a ransom note, typically named "README.txt," instructing victims on how to pay the ransom to obtain the decryption key. The malware often spreads through phishing emails with malicious attachments or by exploiting vulnerabilities in software and operating systems. Razr employs strong encryption algorithms, making it challenging to decrypt files without the attackers' key.
Read More
Maze screenshot
Maze
maze ransomware
Maze is ransomware — a malware type that encrypts the victim’s files and restores the data in exchange for a ransom payment. One of the most distinguishable features of Maze is that it is one of the first malware of the kind to publicly release stolen data.
Read More
Gh0st RAT screenshot
Gh0st RAT
gh0st
Gh0st RAT is a malware with advanced trojan functionality that enables attackers to establish full control over the victim’s system. The spying capabilities of Gh0st RAT made it a go-to tool for numerous criminal groups in high-profile attacks against government and corporate organizations. The most common vector of attack involving this malware begins with spam and phishing emails.
Read More