# Interlock

> As of 2026-09-04, Interlock is a threat actor tracked by Threadlinqs Intelligence across 4 threats spanning data breach, threat intel, vulnerability. ATT&CK coverage spans 51 techniques across 15 tactics in 4 of 4 tracked threats. Most-observed techniques: T1082 (System Information Discovery), T1190 (Exploit Public-Facing Application), T1003 (OS Credential Dumping).

- **Tracked threats:** 4
- **Categories:** DATA_BREACH, THREAT_INTEL, VULNERABILITY
- **As of:** 2026-09-04

## ATT&CK techniques observed

51 techniques observed across 4 of 4 tracked threats. Tactics: Credential Access (6), Discovery (6), Persistence (6), Command and Control (5), Execution (5), Stealth (formerly Defense Evasion) (5).

- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 3 of 4 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 3 of 4 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 2 of 4 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 4 tracked threats
- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 2 of 4 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 2 of 4 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 2 of 4 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 2 of 4 tracked threats
- [T1070](https://intel.threadlinqs.com/technique/T1070) Indicator Removal — Stealth (formerly Defense Evasion) — observed in 2 of 4 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 2 of 4 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 2 of 4 tracked threats
- [T1219](https://intel.threadlinqs.com/technique/T1219) Remote Access Tools — Command and Control — observed in 2 of 4 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 2 of 4 tracked threats
- [T1490](https://intel.threadlinqs.com/technique/T1490) Inhibit System Recovery — Impact — observed in 2 of 4 tracked threats
- [T1014](https://intel.threadlinqs.com/technique/T1014) Rootkit — Stealth (formerly Defense Evasion) — observed in 1 of 4 tracked threats

## Tracked threats

- [DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patients](https://intel.threadlinqs.com/threat/TL-2026-2328) — HIGH
- [Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum Crypto](https://intel.threadlinqs.com/threat/TL-2026-2310) — HIGH
- [Interlock Ransomware Exploits Cisco FMC Zero-Day (CVE-2026-20265) Amid March 2026 CVE Surge](https://intel.threadlinqs.com/threat/TL-2026-0356) — CRITICAL
- [Cisco Secure Firewall Management Center Insecure Java Deserialization RCE (CVE-2026-20131) — Interlock Ransomware Zero-Day Exploitation](https://intel.threadlinqs.com/threat/TL-2026-0260) — CRITICAL

## Related CVEs

6 CVEs referenced by tracked Interlock activity.

- [CVE-2026-20265](https://intel.threadlinqs.com/cve/CVE-2026-20265)
- [CVE-2026-20131](https://intel.threadlinqs.com/cve/CVE-2026-20131)
- [CVE-2025-68947](https://intel.threadlinqs.com/cve/CVE-2025-68947)
- [CVE-2024-4345](https://intel.threadlinqs.com/cve/CVE-2024-4345)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Interlock
