Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Interlock

156
Global rank
179 infographic chevron month
Month rank
172
Week rank
0
IOCs

Interlock is a relatively recent entrant into the ransomware landscape. First identified in 2023, it's a multi-functional malware strain used in ransomware-as-a-service (RaaS) operations.

Ransomware
Type
Unknown
Origin
1 October, 2023
First seen
24 July, 2026
Last seen

How to analyze Interlock with ANY.RUN

Type
Unknown
Origin
1 October, 2023
First seen
24 July, 2026
Last seen

IOCs

IP addresses
216.239.34.36
142.250.154.156
74.178.76.128
142.251.20.94
184.86.251.19
48.209.138.189
142.251.110.94
151.101.192.176
142.251.14.132
3.160.150.61
88.221.169.205
23.11.40.157
147.123.136.167
88.221.169.152
142.250.154.95
142.251.127.97
34.160.81.0
142.251.20.113
48.192.1.64
172.66.158.149
Hashes
81b2bd4ea98c8db66554fbc8d7637a1a69a130f331feb732b75caab4c4868fd5
f3c0fa2cd71bb91d0e3acf5d77b93c49a184e9ad941532ca8c07c82eb0bd6a6c
20de375707692099b3132084695377ce5fec0aec05813dedcce094b8eda44386
85f08b5f51e36ca7e961a033c6bb61d7f0e44aa0984646383ecac648e98fdcc8
7bfbc8202b8cdbdcc597a0e789240f0dc0b0e94fa6597e576eaf436bc6223e18
007d9f9bae4f96afc98161c40cba00d33c7d8cd5684cc97d57d1cadce77a8ff2
0b4db7a09ee3306e969fe0b32228422f223eb2f71bd5d1ec1a0d9ef16b405c58
82b9db18853a960a88dc865714229eeb57979339be6c49ddecfda0766eec9d4b
9f7a00b7385b15a3155dd0ace08d726f5a3b0196ebb4fb0b0aafebf770bc44e1
a0223b245c2a52e9671fa60bddb32283e43b66c363cc82a9af3663dc055fad3c
084134eab56d3f2b14a3a777c078f7b0119eeba0641af54dac74a00fd367cfa7
35329fdadfeeb2377d06e27515a597bd46832763f62af804326e30cdd561f488
c64de57e9638408f346bbbf01d65e5836d89ebc90e77d8fd9243abd471868f8a
c66fd951d73a23f35a6b656af29172e660e8324a2ea64852baf9fb2e0080a728
31b94b01d6d347ac690aad1476cdf1c99634d38a4285d2e8389bc93be8249f28
e6cdac967faaeec38d8496525aeac902f6c7df0928b16926ca1bc762dfbed7e4
6f02ece7c656e19bd45c9d72f810cd51a14020d6d06e548b8d4edf2b73551c7e
b84ccbb4efa111620444855df8d2f23cab729c22a319cb4a1499ad9b2ba142fa
31a44e0c7ef8d1b5c89637e66f792b056fd5b8fe081fc1e7c625d1a4a1d96f85
2fde88e5e4607cee224bcf6be03e4307bc322f8be13a28ceeb35946a6e7a592c
Domains
googleads.g.doubleclick.net
www.googletagmanager.com
dc10-gw.limewire.network
safebrowsing.googleapis.com
slscr.update.microsoft.com
www.google.com
example.org
firefox-settings-attachments.cdn.mozilla.net
e40636.dsca.akamaiedge.net
www.youtube.com
ep1.adtrafficquality.google
region1.google-analytics.com
tagesschau.de
stripecdn.map.fastly.net
file.io
js.stripe.com
google.com
push.services.mozilla.com
visit-server.inmobi-choice.io
www.gstatic.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaagb6jmmcovb6saaaaaaay%3d
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=task&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=4&cvid=c9d73b5228fb4db0952860a2f890d5a9&ig=b9bc61413d4945378e69eced8a72d1d3
https://www.bing.com/manifest/threshold.appcache
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=ta&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=2&cvid=c9d73b5228fb4db0952860a2f890d5a9&ig=7cc151c4fcfc4e1b9eafc5d19b84a7d6
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=t&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=1&cvid=c9d73b5228fb4db0952860a2f890d5a9&ig=ebf31cd3c9fb42898d04990fbf32a3e7
https://www.bing.com/dsb/scenario?name=trendingsearchwithcache&cc=us&setlang=en-us
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=tas&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=3&cvid=c9d73b5228fb4db0952860a2f890d5a9&ig=4b6f2c6db86b45ff842122a0afd95bfd
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://www.bing.com/as/api/windowscortanapane/v2/init
https://www.bing.com/th?id=odswg.465296d7-3ab4-4023-8bca-7c76a2283338&pid=dsb
https://www.bing.com/rb/1d/cc,nc/8qgg5w3ncsqflirnejktkex2-pa.css?bu=ehn6cyakexmqcnmwcpgkexl5owqlcnl5&or=w
https://www.bing.com/rb/1d/cc,nc/dkse3syhvijzh9mpm4nc3lq7l5i.css?bu=d5cjnamecxmpcb4jxal51al5eeojexmlcg&or=w
https://www.bing.com/th?id=odswg.b223c4b1-3438-4684-8e9b-a0d8aa4c1617&pid=dsb
https://www.bing.com/rb/2h/jnc,nj/mdduuzmrcgufo06rvyb6gch2ypi.js?bu=aogelau&or=w
https://www.bing.com/rp/0ogclsbcqza1essaleoftg07bse.br.js
https://www.bing.com/rp/1o3ej2dhegimk3wam0fnjqgbure.br.js
https://www.bing.com/rp/3kqqw2nfujaikg40-4nmnx8qade.br.js
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2658
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7601
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10652
comments 0

What is Interlock malware?

Interlock is a modular ransomware tool that enables hackers to lock and encrypt files, exfiltrate data, and demand ransoms in double extortion schemes. It targets both Windows and Linux systems, with 64-bit executables (Windows PE and Linux ELF formats).

Interlock gained attention for its stealth and customizability, starting from targeting small and midsize enterprises with limited cybersecurity maturity and proceeding to industry leaders for really big ransoms. Healthcare organizations are another common victim of Interlock.

Discover detailed investigation into Interlock attacks on U.S. hospitals and healthcare providers.

Like many modern malware strains, Interlock leverages common but effective attack vectors. Adversaries send malicious attachments or links in well-crafted spear phishing messages, sometimes including QR codes or cloud-sharing links to bypass email filters. They exploit vulnerabilities, purchase credentials from initial access brokers and employ malvertising — drive-by downloads from fake ads or compromised legitimate websites.

Upon a successful infiltration, Interlock exploits active directory misconfigurations and uses PowerShell, WMI, and RDP for lateral movement within the network. Having established itself in the system, it dumps credentials from memory, exfiltrates data before encryption (double extortion), encrypts data with strong algorithms (often AES or ChaCha20) and greets the victim with a customized ransom note. Optionally, Interlock can recruit keyloggers, browser data collectors, and screenshot capturing.

The malware affects both Windows and Linux environments, with binaries tailored for each, indicating broad compatibility and intent to hit diverse infrastructures. It may use scheduled tasks or registry modifications to maintain access, ensuring it can resume operations after a reboot.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Interlock Ransomware’s Prominent Features

Interlock poses significant risks due to its:

  • Sector Impact: Healthcare and government sectors are particularly vulnerable due to their reliance on uptime and data confidentiality. Disruptions can lead to life-threatening delays or exposure of classified information.
  • Big-Game Hunting: Interlock targets high-value organizations, demanding large ransoms, but can also cripple smaller entities or those with limited cybersecurity budgets.
  • Broad Targeting: Its ability to hit both Windows and Linux systems makes it a threat to diverse environments, from enterprise servers to critical infrastructure.
  • Double-Extortion Strategy: The threat of data leaks amplifies financial and reputational damage, especially for organizations handling sensitive data.
  • Persistence: Its ability to maintain access increases the risk of repeated attacks or secondary payloads.

Interlock is notable for deploying a rare FreeBSD encryptor, aiming at critical infrastructure servers (e.g., web hosting, mail servers). While specific FreeBSD attacks are not yet detailed, this capability suggests potential for broader disruption in future incidents.

Interlock’s Execution Process and Technical Details

To watch Interlock enforce its varying attack scenarios, search for this malware via ANY.RUN’s Threat Intelligence Lookup and explore the analyses of its samples publicly submitted in the Interactive Sandbox.

threatName:"interlock"

Interlock ransomware samples in ANY.RUN Sandbox Interlock ransomware analyses in ANY.RUN's Interactive Sandbox

Let’s watch one of the analysis sessions closer

The execution chain of Interlock ransomware unfolds in several stages, employing both deception and sophisticated tools to compromise and extort victims. It typically begins with a drive-by compromise, where users are tricked into visiting phishing websites that appear legitimate. These sites offer fake updates or tools, which, once downloaded, infect the user’s device with malware. For example, malicious software might be disguised as a legitimate update for a popular application such as Chrome or Microsoft Edge. In one observed instance, the executable file was named upd_9488679.exe, where upd is short for “update,” although it can also appear under names like Update or ChromeSetup.

Once inside the system, attackers may deploy malicious payloads or execute harmful commands to take full control of the victim’s network. Prior to encryption, they often exfiltrate sensitive data as part of a double extortion strategy, threatening not only to encrypt the data but also to release the stolen information publicly if the ransom is not paid.

Next, the Interlock ransomware encryptor is deployed, appending the .interlock extension to files and dropping a ransom note titled !README!.txt in affected directories. This note typically provides instructions on how to contact the attackers and pay the ransom. The reliance on double extortion further pressures victims, who risk losing both access to their data and control over the disclosure of sensitive information.

Following its main functions, the ransomware may erase Windows event logs to conceal evidence of its activities. It can also delete its own binary after encryption, further complicating forensic analysis and recovery efforts.

Interlock ransomware analysis in ANY.RUN A sample of Interlock detonated inside ANY.RUN's Interactive Sandbox

What are the examples of the best-known Interlock attacks?

  • Wayne County, a government entity in Michigan, was hit by Interlock in early October 2024. The breach disrupted local government operations, potentially affecting public services. Interlock demanded a ransom, reportedly ranging from hundreds of thousands to millions of dollars, though it’s unclear if the ransom was paid.
  • Brockton Neighborhood Health Center was breached by Interlock, with the attack going undetected until December 17, 2024. Attackers used a fake Google Chrome updater to gain initial access, deploying a remote access tool (RAT) to exfiltrate sensitive patient data and encrypt files. The delayed detection allowed Interlock to maintain persistence for nearly two months.
  • Interlock claimed responsibility for attacking Andretti Indoor Karting & Games — a U.S. entertainment chain — in March 2025, alleging they stole 1.2 TB of data, including W-9 forms, financial records, and passports. The attack led to a temporary closure of multiple locations. This attack showed Interlock’s willingness to target non-critical sectors like entertainment, broadening their victim pool.

Gathering Threat Intelligence on Interlock malware

Integrating threat intelligence into security operations is much more efficient than paying huge ransoms to Interlock operators or dealing with devastating aftermath of data loss and leaks. Focus on TTPs (tactics, techniques, procedures) shared by TI reports, such as phishing, scheduled tasks to anticipate attack vectors.

Leverage ANY.RUN’s Threat Intelligence Lookup to hunt for IOCs specific to Interlock, like domains, IPs, or file hashes.

Each analysis session in the Sandbox contains a number of IOCs. Use them as search requests to TI Lookup for further exploring the threat and gathering data for monitoring and detection.

Interlock malicious files Files found in an Interlock sample during Sandbox analysis

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Interlock is a young ransomware market player yet already notorious for its big ransom appetites, opportunistic targeting across various sectors, and sophisticated tactics to infiltrate systems, exfiltrate data, and disrupt operations. The group's activities have had significant impacts on the affected organizations, leading to operational downtime, data breaches, and potential financial losses.

To avoid becoming the next victim, reinforce your proactive cybersecurity efforts with actionable data brough to you by threat intelligence.

Start with 50 requests in TI Lookup to collect IOCs on Interlock and be ready to detect and respond

HAVE A LOOK AT

Phishing kit screenshot
Phishing kit
tycoon evilproxy sneaky2fa
Phishing kits are pre-packaged sets of malicious tools designed to make it easy for cybercriminals to launch phishing attacks. These kits replicate legitimate websites, steal credentials, and often include backend infrastructure for managing stolen data.
Read More
Phobos screenshot
Phobos
phobos ransomware
Phobos is a ransomware that locks or encrypts files to demand a ransom. It uses AES encryption with different extensions, which leaves no chance to recover the infected files.
Read More
Moonrise screenshot
Moonrise
moonrise
Moonrise RAT is a newly discovered Go-based remote access trojan with zero detections at launch, featuring credential theft, keylogging, webcam access, clipboard hijacking, and UAC bypass.
Read More
SSLoad screenshot
SSLoad
ssload
SSLoad is a malicious loader or downloader that is used to infiltrate target systems through phishing emails, perform reconnaissance and transmit it back to its operators delivering malicious payloads. To avoid detection, SSLoad employs various encryption methods and delivery techniques highlighting its versatile nature and complexity. It is believed to be a part of Malware-as-a-Service (MaaS) operation given its diverse delivery methods and implemented techniques.
Read More
FatalRAT screenshot
FatalRAT
fatalrat
FatalRAT is a malware that gives hackers remote access and control of the system and lets them steal sensitive information like login credentials and financial data. FatalRAT has been associated with cyber espionage campaigns, particularly targeting organizations in the Asia-Pacific (APAC) region.
Read More
Virlock screenshot
Virlock
virlock
Virlock is a unique ransomware strain that combines encryption capabilities with file infection techniques. First observed in 2014, it stands out due to its polymorphic nature and ability to embed its code into compromised files, ensuring continued propagation. Once it infects a system, it encrypts files and locks the screen, demanding a ransom for file recovery and system access.
Read More