Interlock is a financially motivated ransomware and data-extortion group first observed in September 2024. A joint FBI, CISA, HHS and MS-ISAC advisory describes opportunistic attacks against businesses and critical-infrastructure organizations in North America and Europe. AWS reported an active Interlock campaign in early 2026, but public reporting does not identify the operators or establish a state sponsor.
Activity and targeting
Interlock has affected organizations across multiple sectors rather than a single fixed victim set. The joint advisory documents activity against businesses and critical infrastructure in North America and Europe. Amazon threat intelligence assessed that education represented the largest share of observed activity, followed by engineering, architecture and construction, manufacturing and industrial organizations, healthcare, and government and public-sector entities. These observations support opportunistic targeting and do not establish that every claimed victim or sector pattern reflects a verified intrusion.
Methods and operational characteristics
Interlock uses double extortion: operators steal data, encrypt systems and threaten publication through leak and negotiation infrastructure. The joint advisory documents Windows and Linux encryptors, virtual-machine targeting, unique victim codes and Tor-based contact. It also reports drive-by downloads from compromised websites, fake browser or security-software updates, ClickFix social engineering, PowerShell-based remote access, credential theft, RDP and legitimate remote-administration tools for lateral movement, and Azure tools for data exfiltration. Cisco Talos additionally analyzed Windows and Linux variants, the Worldwide Secrets Blog leak site, a Tor negotiation workflow and an intrusion that used a fake browser update, AnyDesk, PuTTY and AzCopy before encryption.
Interlock’s access methods have continued to evolve. In March 2026, AWS reported that the group had exploited CVE-2026-20131 in Cisco Secure Firewall Management Center before public disclosure. AWS linked the campaign through convergent technical and operational indicators, including Interlock-branded ransom notes, a known Tor portal and per-victim organization identifiers, and documented custom JavaScript and Java remote-access tools, memory-resident access, disposable proxy infrastructure and legitimate-tool abuse.
What type of group is it?
Interlock is best characterized as a financially motivated ransomware group. The reviewed sources support criminal extortion as its operating model and do not establish political motivation, government direction or state alignment. Cisco Talos assessed with low confidence that Interlock may have emerged from Rhysida operators or developers based on code, tooling and behavioral overlap. That hypothesis does not establish a rebrand, shared identity or confirmed organizational relationship, so Interlock remains a distinct actor record.