U.S. Department of Homeland Security Issues Joint Advisory on Interlock Ransomware

The U.S. Department of Homeland Security's Cybersecurity and Infrastructure Security Agency, along with the Federal Bureau of Investigation, Department of Health and Human Services, and Multi-State Information Sharing and Analysis Center, recently released a joint advisory to inform the public about the Interlock ransomware variant. This advisory comes after the FBI's investigations and trusted third-party reporting identified known Interlock ransomware IOCs and TTPs. The Interlock ransomware variant has been observed targeting various business, critical infrastructure, and other organizations in North America and Europe since late September 2024.

Key Takeaways:

  • The Interlock ransomware variant was first observed in late September 2024, targeting various business, critical infrastructure, and other organizations in North America and Europe.
  • The FBI maintains that these actors target their victims based on opportunity, and their activity is financially motivated.
  • FBI is aware of Interlock ransomware encryptors designed for both Windows and Linux operating systems.
  • Actors obtain initial access via drive-by download from compromised legitimate websites, which is an uncommon method among ransomware groups.
  • Actors were also observed using the ClickFix social engineering technique for initial access, in which victims are tricked into executing a malicious payload under the guise of fixing an issue on the victim's system.
  • Actors then use various methods for discovery, credential access, and lateral movement to spread to other systems on the network.
  • Interlock actors employ a double extortion model in which actors encrypt systems after exfiltrating data, which increases pressure on victims to pay the ransom to both get their data decrypted and prevent it from being leaked.
  • The FBI, CISA, HHS, and MS-ISAC encourage organizations to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of Interlock ransomware incidents.

Statistics:

  • The interlock ransomware variant was first observed in late September 2024, targeting various business, critical infrastructure, and other organizations in North America and Europe.
  • The FBI has identified Interlock ransomware encryptors designed for both Windows and Linux operating systems.
  • Actors use the ClickFix social engineering technique for initial access, where victims are tricked into executing a malicious payload under the guise of fixing an issue on the victim's system.
  • Interlock actors employ a double extortion model, where actors encrypt systems after exfiltrating data, which increases pressure on victims to pay the ransom to both get their data decrypted and prevent it from being leaked.

Sources:

  • "Stop Ransomware: Interlock" (2025, July 22). Cybersecurity and Infrastructure Security Agency.
  • https://www.cisa.gov/sites/default/files/2025-07/aa25-203a-stopransomware-interlock-072225.pdf