Interlock is a financially motivated ransomware and data-extortion threat actor active by at least 2024 and still operating in 2026. The group conducts double-extortion operations, combining network intrusion and data theft with threats to publish stolen information on a leak site when victims refuse to pay. Reported victims span healthcare, education, government, manufacturing, logistics, nonprofit, and community-service organizations in multiple countries, including the United States, Canada, the United Kingdom, Ireland, and Australia. Interlock has been linked to opportunistic exploitation of high-severity enterprise vulnerabilities for initial access. In 2026, the group was identified exploiting the Cisco Secure Firewall Management Center zero-day CVE-2026-20131 before public disclosure and patching, demonstrating capability to weaponize perimeter-device flaws against enterprise environments. The group has also been associated with broader exploitation activity tracked in enterprise vulnerability reporting. Interlock is additionally associated with social-engineering-driven intrusion chains, particularly ClickFix-style lures that trick users into executing malicious commands. Reporting ties the operation to repeated use of such techniques over at least a year, often as pre-ransomware access activity. Malware and tooling linked to these campaigns include NodeSnake RAT, HijackLoader, and SnappyClient. NodeSnake in particular has been tied to the Interlock operation and showed signs of ongoing development, including enhanced screenshot collection and possible affiliate-tracking features. Infrastructure used in some of this activity has also been publicly linked to the KongTuke initial access broker, suggesting reliance on external access-enablement or affiliate relationships. Observed victimology indicates broad sector targeting rather than a narrow vertical specialization, though healthcare, public-sector, and education organizations have featured prominently in public reporting. Interlock has claimed attacks affecting municipal government entities, treatment providers, dental and hearing-care organizations, schools, and private companies. Publicly reported incidents indicate the group frequently emphasizes theft of sensitive personal, medical, financial, employee, customer, contractual, and internal business records to increase extortion pressure. Interlock is best characterized as a ransomware gang rather than a nation-state actor. No high-confidence public attribution in this material ties it to a specific government. Known aliases include interlock, interlock_group, interlock_ransomware, and interlock_ransomware_gang.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
CVE-2026-20131 (CVSS 3.1 skóre 10.0) Kritická zraniteľnosť s označením CVE-2026-20131 spočíva v nezabezpečenej deserializácii používateľských vstupov. Vzdialený neautentifikovaný útočník by ju mohol zneužiť na vzdialené vykonanie kódu Java s oprávneniami používateľa root. Na to potrebuje poslať špeciálne vytvorený serializovaný objekt Java na webové manažmentové rozhranie zraniteľného zariadenia. [Aktualizácia 19.3.2026] Ransomvérová skupina Interlock aktívne zneužívala kritickú zero-day zraniteľnosť CVE-2026-20131 v softvéri Cisco Secure Firewall Management Center už od konca januára 2026, približne mesiac pred jej zverejnením a opravou.
Hotta Killer (Interlock): exploits a gaming anti-cheat driver zero-day (CVE-2025-61155) to attack FortiEDR
Local privilege escalation exploit CVE-2023-36036 (JunkFiction-crypted) ... CVE CVE-2023-36036 Local privilege escalation exploit used by Interlock and ModeloRAT operators
83 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group noted as having claimed Irish victims.
Mentioned only in passing as part of a list of campaigns tied to BitLaunch IP reporting.
Conducting a ransomware attack and associated data breach against Paragon Store Fixtures, resulting in exposure of contracts, architectural plans, confidential design documentation, and client-related intellectual property.
Conducting a ransomware attack and data extortion against Centre for Newcomers, claiming theft of 380 GB of personal client data, financial information, and HR planning/policy data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.