Fake Interpol Investigation Emails Deliver Custom Ransomware to Small Businesses — Threadlinqs Intelligence
As of 2026-07-02, Fake Interpol Investigation Emails Deliver Custom Ransomware to Small Businesses is a medium-severity ransomware threat attributed to independent operator, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-1082 · Severity: MEDIUM · Status: ACTIVE · Category: RANSOMWARE
Attribution: independent operator · FINANCIAL
A phishing campaign impersonates Interpol's cybercrime investigation unit, pressuring small and mid-sized businesses across the US, Europe, Asia, and the Middle East into opening a password-protected
Bitdefender's Antispam Lab identified an active social-engineering campaign in which threat actors send emails posing as Interpol's cybercrime investigation unit, claiming the recipient's organization is under review for suspicious account or system activity and that investigators have obtained 'video material' as evidence. The email uses formal language and urgent subject lines to convince employees their organization faces a compliance or security review, then links to a Proton Drive-hosted, password-protected archive named archive.rar (the password is included in the email body to lower suspicion and bypass automated sandboxing/email-gateway scanning that cannot open password-protected files). Inside archive.rar is a nested, multi-layered archive structure that ultimately reveals an executable disguised as a video file. When run, the file deploys a custom-built ransomware payload that encrypts files across all available local drives and drops a ransom note reading in part: 'Your computer has been compromised, and you will not be able to recover your encrypted files without the decryption key. Do not delete any files or change their locations. Do not scan your computer, as this may complicate the recovery process. We are available only through Tox.' The note provides no fixed ransom amount, requiring victims to make direct contact via a Tox chat ID (an encrypted P2P instant-messaging protocol) rather than a dedicated dark-web negotiation site — a strong indicator this is an independent actor or small group rather than an established ransomware-as-a-service (RaaS) operation. Bitdefender researcher Viorel Vrabie noted the malware's decryption functionality and the encryption/decryption password are embedded directly in the malware's own code, meaning victims can technically recover files without paying or contacting the attacker at all. Bitdefender assessed the malware was likely built using publicly available code, templates, tutorials, or AI-assisted coding, though no obvious/conclusive signs of AI assistance were detected in the sample; researchers characterized the actor as 'a less sophisticated group or individual rather than an established ransomware group,' relying primarily on psychological manipulation (fear of law-enforcement action, threats that scanning or moving files will 'complicate the recovery process') rather than technical sophistication. No data-exfiltration activity was observed, distinguishing this from double-extortion RaaS campaigns. The lure specifically targets small and mid-sized businesses across the food/agriculture, legal services, pharmaceutical, media, technology, and finance sectors in the United States, Europe, Asia, and the Middle East — organizations judged more likely to lack dedicated IT/security teams (security responsibilities often shared among employees wearing multiple hats) and more likely to react to a law-enforcement-branded threat out of fear of regulatory or reputational consequences. No CVE or software vulnerability is exploited; the entire chain relies on social engineering, authority/brand impersonation, and archive/file-type obfuscation to induce manual execution.
Target sectors: food and agriculture, legal services, pharmaceuticals, news - media, technology, finance
Target regions: united states of america, Europe, Asia, Middle East
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, MEDIUM, threat intelligence, cybersecurity, T1591, T1588, T1583, T1585, T1566, T1566, T1204, T1036, T1036, T1027