216.73.217.22

Interlock Ransomware: New Techniques, Same Old Tricks

· Published 30/01/2026 08:23 · Modified 30/01/2026 08:50

Export JSON

Essential information

Published
30/01/2026 08:23
Modified
30/01/2026 08:50
Tags
2026-01-30 data exfiltration education sector hotta killer interlockrat lateral movement mintloader nodesnakerat persistence ransomware zero-day
Related entities
1 vulnerabilities (cve), 8 observables, 1 intrusion sets (apt), 10 techniques (mitre), 4 malware, 25 others

Description

The Interlock group continues to target organizations worldwide, particularly in the UK and US . Unlike other groups, Interlock operates independently, developing and using their own malware. This article details a recent intrusion, highlighting the group's ability to adapt techniques and tooling. The attack involved multiple stages, including initial access via , use of custom malware like and , and deployment of a novel process-killing tool exploiting a vulnerability. The adversaries used various techniques for , , and before ultimately deploying . The intrusion demonstrates the importance of threat hunting and integrating threat intelligence to identify compromises before significant impact occurs.

External references