interlock
Known ransomware group Dormant / low-volume
Interlock is a ransomware operation active since 2024 that targets both Windows and FreeBSD/Linux systems, notable for using fake browser-update lures and "ClickFix" social engineering for initial access. It has struck healthcare and critical-infrastructure organizations.
1
Total Claims
1
Critical
—
Records Claimed
1
Industries Hit
Active span: May 11, 2026 – May 11, 2026 · 1 organizations targeted
Dormant / low-volume
Actor Threat Profile
Activity Timeline
Peak: May 2026 (1)May 2026
LessMore
May 2026Top Targeted Industries
Healthcare 1
Tradecraft & Infrastructure
11
Documented tools
0 / 0
MITRE tactics / techniques
2
Known leak sites
DefenseEvasionDiscoveryEnumExfiltrationLOLBASNetworkingOffsecRMM-Tools
Full intelligence profile on ransomware.live →