Interlock

Interlock — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

InterlockConfidence: High

Ransomware

Motivation: Financial

6Attributed Breaches Circulating
HighAttribution Confidence
RansomwareActor Type

Overview

Breaches organizations via drive-by downloads and the ClickFix social-engineering technique, then runs double extortion, active since around September 2024 across North America and Europe. Not a RaaS but a smaller dedicated team building its own malware; ransom notes carry a unique code and a Tor .onion contact. Subject of CISA advisory AA25-203A.

Tactics, Targeting & TTPs

Not a RaaS: a smaller dedicated team developing its own malware. Initial access via drive-by downloads from compromised sites and the ClickFix social-engineering technique; encrypts VMs; ransom notes carry a unique code and a Tor .onion contact rather than an up-front demand. Subject of CISA advisory AA25-203A (2025).

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation