Interlock is a financially motivated ransomware and data-extortion operation first observed in September 2024. Also known as Interlock Group, Interlock Ransomware, and Interlock Ransomware Gang, it targets organizations across healthcare, education, government, defense, manufacturing, and financial services, with a prominent focus on the United States. Its double-extortion model combines data theft and system encryption with threats to publish stolen information on a dedicated leak site. Its country of origin and any nation-state sponsorship are not established. Interlock uses compromised websites, counterfeit browser and VPN updates, trojanized installers, and ClickFix social engineering to obtain initial access. ClickFix lures induce users to execute attacker-supplied commands, leading to backdoors and other payloads. The group has also exploited network-edge devices, including zero-day exploitation of CVE-2026-20131 in Cisco Secure Firewall Management Center during 2026. Interlock-associated infection chains have been linked to the TAG-124 traffic distribution system, but shared infrastructure does not establish common ownership or operator identity. Its intrusion toolkit includes credential stealers, keyloggers, PowerShell backdoors, and custom remote-access malware. Associated NodeSnake and Node.js-based Interlock RAT activity uses the legitimate Node.js runtime to execute malicious JavaScript. These implants support host and Active Directory reconnaissance, identification of backup infrastructure, remote command execution, and SOCKS proxying. Persistence mechanisms include scheduled tasks and user-level autorun entries. Living-off-the-land techniques, obfuscated scripts, and abuse of legitimate signed software help evade detection. Interlock uses remote-access utilities for continued access and lateral movement, and cloud-storage tooling for data exfiltration. Major healthcare attacks include the April 2025 compromise of DaVita, in which attackers stole data and encrypted internal systems, and the attack on Kettering Health that disrupted medical-center operations. Its targeting of healthcare and other essential services has caused operational disruption as well as exposure of sensitive personal and business information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Lastly, in a March 2026 report, Amazon threat intelligence documented an Interlock intrusion exploiting CVE-2026-20131, demonstrating the group’s ability to exploit network edge devices to achieve initial access.
Hotta Killer (Interlock): exploits a gaming anti-cheat driver zero-day (CVE-2025-61155) to attack FortiEDR
Local privilege escalation exploit CVE-2023-36036 (JunkFiction-crypted) ... CVE CVE-2023-36036 Local privilege escalation exploit used by Interlock and ModeloRAT operators
The reported May 2025 AMTEC/National Defense Corporation attack included "Exploitation of unpatched CVE-2024-21407 (Windows Kernel privilege escalation flaw)."
112 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reportedly conducted a ransomware attack against Shalom Christian Academy, a US school. The incident report includes a claim of publicly leaking sensitive student, family, donor, and employee records, including educational, health, financial, and internal security information. The reported breach and discovery date is October 9, 2026; the content provides no independent verification of the leak.
Interlock claims to have publicly leaked confidential student, employee, donor, and internal security records from Shalom Christian Academy, a US school. The victim was discovered on the leak site on October 9, 2026; no data volume, ransom amount, or payment deadline is stated.
Reportedly conducted a ransomware attack against Riviera Healthcare Center, a US skilled nursing and rehabilitation facility. The report states that patient health information, payment records, and employee/HR data were exposed, with the breach discovered on October 7, 2026, at 18:00 UTC. It provides no technical evidence or details establishing the attack mechanism.
Interlock claims confidential data exposure at Riviera Healthcare Center, a US skilled nursing facility, including patient PHI, payment records, and employee/HR data. The victim was listed as discovered on October 7, 2026; no data volume, ransom demand, deadline, or supporting samples are provided.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.