Activity timeline
Interlock appears in 4 tracked threats between and ; the busiest month was 2026-09 with 2 reports.
ATT&CK techniques observed
- T1082 System Information Discovery — Discoveryobserved in 3 of 4 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 4 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 2 of 4 tracked threats
- T1005 Data from Local System — Collectionobserved in 2 of 4 tracked threats
- T1018 Remote System Discovery — Discoveryobserved in 2 of 4 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 2 of 4 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 2 of 4 tracked threats
- T1059.001 PowerShell — Executionobserved in 2 of 4 tracked threats
- T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 2 of 4 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 2 of 4 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 2 of 4 tracked threats
- T1219 Remote Access Tools — Command and Controlobserved in 2 of 4 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 2 of 4 tracked threats
- T1490 Inhibit System Recovery — Impactobserved in 2 of 4 tracked threats
- T1014 Rootkit — Stealth (formerly Defense Evasion)observed in 1 of 4 tracked threats
Tracked threats
- DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M PatientsHIGH
- Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum CryptoHIGH
- Interlock Ransomware Exploits Cisco FMC Zero-Day (CVE-2026-20265) Amid March 2026 CVE SurgeCRITICAL
- Cisco Secure Firewall Management Center Insecure Java Deserialization RCE (CVE-2026-20131) — Interlock Ransomware Zero-Day ExploitationCRITICAL