Interlock is a financially motivated ransomware and data-extortion threat actor active by at least 2024 and prominently observed through 2025 and 2026. The group operates as a conventional ransomware crew that claims intrusions on a public leak site, steals victim data for double-extortion leverage, and threatens publication when ransom demands are not met. Reported victims span education, healthcare, local government, nonprofit, logistics, and other critical or business service sectors, with observed targeting in the United States, Canada, and Australia. Interlock has been associated with attacks against schools, healthcare providers, municipalities, and private-sector organizations, indicating broad opportunistic targeting rather than a narrowly specialized victim profile. Multiple publicly reported incidents attribute to Interlock both network compromise and large-scale data theft, followed by extortion demands and leak-site publication. Healthcare and other critical infrastructure organizations have been repeatedly named among its victims. Interlock is best understood as part of the broader cybercrime ransomware ecosystem rather than a state-sponsored or geopolitically aligned actor. Reporting also places it among ransomware groups that may receive access from initial access brokers. In particular, Woodgnat, also known as KongTuke, has been publicly linked to intrusion activity involving Interlock as well as other ransomware brands. Malware and access tooling such as ModeloRAT and Mistic have been discussed in connection with access-broker operations tied to ransomware ecosystems that include Interlock, although such reporting generally supports an ecosystem relationship rather than confirmed exclusive ownership or direct development by Interlock itself. Tradecraft associated with operations linked to Interlock’s ecosystem includes social-engineering-driven initial access, abuse of legitimate administrative utilities, PowerShell-based execution chains, credential theft, DLL sideloading, in-memory payload execution, and stealthy persistence mechanisms. Where access-broker involvement is present, victims may first be compromised through fake technical support or browser-alert lures, compromised web infrastructure, or chat-based impersonation, after which access is monetized to ransomware operators. Interlock’s own extortion pattern is characterized by public victim naming, claims of exfiltrated data volume, and coercive threats to release stolen information. Known aliases include interlock, interlock_group, interlock_ransomware, and interlock_ransomware_group. No high-confidence evidence in the available information supports attribution to a nation state.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
CVE CVE-2026-20131 Network edge device vulnerability exploited by Interlock for initial access
Hotta Killer (Interlock): exploits a gaming anti-cheat driver zero-day (CVE-2025-61155) to attack FortiEDR
Local privilege escalation exploit CVE-2023-36036 (JunkFiction-crypted) ... CVE CVE-2023-36036 Local privilege escalation exploit used by Interlock and ModeloRAT operators
83 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware/data extortion attack against Borger ISD and claiming to have leaked 330 GB of stolen data.
Claimed responsibility for the October 2024 ransomware attack against Drug and Alcohol Treatment Services and stated that 150 GB of data was stolen, later publishing the stolen data on its leak site after the ransom was not paid.
Conducting a ransomware attack and associated data breach against YMCA of Western North Carolina.
Conducted a ransomware-related extortion attack against the City of St. Paul, stole 43 GB of confidential data, posted data on its leak site after the victim refused to pay, and used the threat of public data exposure to pressure payment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.