IN

interlock

Known ransomware group ACTIVE
Currently active

Interlock is a ransomware operation active since 2024 that targets both Windows and FreeBSD/Linux systems, notable for using fake browser-update lures and "ClickFix" social engineering for initial access. It has struck healthcare and critical-infrastructure organizations.

3

Total Claims

1

Critical

—

Records Claimed

3

Industries Hit

Active span: May 11, 2026 – Sep 15, 2026 · 3 organizations targeted

Currently active
Activity 3.0 Severity 6.7 Sectors 4.6 Tooling 0.0

Actor Threat Profile

Activity Timeline

Peak: Sep 2026 (2)
May 2026
LessMore
Sep 2026

Share this profile

Shareable intel card for interlock

Top Targeted Industries

Government & Defense 1
Education 1
Healthcare 1

Tradecraft & Infrastructure

0

Documented tools

0 / 0

MITRE tactics / techniques

2

Known leak sites

Full intelligence profile on ransomware.live →

Claims by interlock

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.