Interlock is a ransomware group first observed in September 2024 that targets critical infrastructure sectors including healthcare, government, education, and technology across North America and Europe using double-extortion, with 57+ claimed victims including a major US dialysis provider exposing over two million patient records.
Genera un perfil del actor con IA (defensivo) cuando lo pidas.
Este grupo no tiene TTPs curadas. Puedes generar un mapeo MITRE ESTIMADO por IA (no confirmado) a partir de su descripción/notas, solo cuando lo pidas.
Para detección/bloqueo en tu EDR/SIEM. Fuente: ransomware.live.
Firma de detección defensiva para este grupo (úsala en tu EDR/SIEM). Fuente: ransomware.live.
/*
Interlock ransomware
*/
rule Interlock_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.interlock"
description = "Detects Interlock ransomware ransom note"
date = "2026-05-04"
severity = 7
score = 70
strings:
$s1 = "!README!.txt" ascii nocase
$s2 = "INTERLOCK" ascii nocase
$s3 = ".interlock" ascii
$s4 = "Interlock" ascii
condition:
2 of them
}
Action Required: Data Breach Notification Your Data Is Now Beyond Your Control We have taken control of your systems, encrypted your critical files, and extracted sensitive data. This is a pivotal moment for your organization—your actions now will determine the outcome. --- What You Need to Understand Your data security was compromised because of insufficient protection. As a result: 1. All access to important files has been restricted through encryption. 2. We possess confidential business records, personal data, and other critical information. 3. If you do not respond within 72 hours, we will initiate the public release of your data, creating irreversible damage. --- The Risks You Face: Failure to act swiftly puts your organization at risk of: - Legal violations under GDPR, GLBA, CCPA, HIPAA, NYDFS Cybersecurity Regulation, and DPA 2018. - Financial penalties for failing to protect Non-Public Information (NPI). - Reputational harm as clients, partners, and the public lose trust in your ability to safeguard their data. --- What You Must Do Immediately: 1. Initiate Communication: - Access our recovery portal using TOR Browser. - Download TOR from [[redactado] - Visit [redactado] using your Organization ID [snip] to start the negotiation process. 2. Alternative Browser Access: - Use Chrome, Edge, or Firefox to open [redactado] - Enter your Organization ID [snip] to receive detailed recovery instructions. --- What Happens Next: - If we do not hear from you within 72 hours, your data will be exposed to the public and sold to interested parties. - The ensuing violations of laws such as GDPR and HIPAA will lead to significant penalties, lawsuits, and regulatory scrutiny. --- Your Responsibility: Your organization is fully accountable for protecting the data it collects. By neglecting this responsibility, you have allowed this situation to unfold. Your chance to regain control is limited—act decisively to avoid catastrophic outcomes.
He performs system administration for domain networks but is unable to ensure his own security. As a result, his data was compromised, and he was caught distributing pornographic content, storing over 200 terabytes of pornographic data on his network-attached storage (NAS). He administers pornographic websites and publishes content there, creates content featuring real people and sells it for money, and engages in blackmail by generating pornographic content using artificial intelligence. He finds victims and demands money from them. Various victims, including minors, as well as prominent public figures and political figures, including President Donald Trump, have been discovered in his computer files. Law enforcement is advised to pay attention to this individual as he is a sexual predator and distributor of pornography. You can view his directory structure, browser profiles, and saved HTML pages, where you can read his 4chan correspondence and much more.
| Organización | País | Sector | Grupo | Descubierta |
|---|---|---|---|---|
| Connell Enterprises LLC | US | Other | — | 14 ago 2026 |
| AngMar Companies | Not Found | — | 11 ago 2026 | |
| Gardiner Family Chiropractic | US | Healthcare | — | 31 jul 2026 |
| Centre for Newcomers | CA | Public Sector | — | 17 jul 2026 |
| Paragon Store Fixtures | US | Manufacturing | — | 17 jul 2026 |
| Converting Equipment International | US | Manufacturing | — | 16 jul 2026 |
| Borger ISD | US | Education | — | 10 jul 2026 |
| YMCA of Western North Carolina | US | Consumer Services | — | 7 jul 2026 |
| Clearview Eye Centre | CA | Healthcare | — | 25 jun 2026 |
| Cold Front Distribution | US | Transportation/Logistics | — | 2 jun 2026 |
| Milano | MX | Retail & E-Commerce | — | 13 mar 2025 |
Las direcciones de los sitios de filtración (.onion) se conocen pero no se publican ni se enlazan. Solo se muestran metadatos públicos. ética
AngMar is a private organization comprised of numerous corporate holdings, LLCs, and companies, operating a network of home health care facilities. They disregard the safety of their clients and the people they care for. As a result, 710 GB of confidential information about the companies they serve has been exposed. Most importantly, patient data has been leaked, including their medical records, medical histories, personal information such as Social Security numbers, home addresses and phone numbers, and much more.
Gardiner Family Chiropractic has been providing medical services to residents of Gardiner and the surrounding area since 1989. However, it is not responsible for its patients and makes no attempt to ensure the security of its stored information. Therefore, patient data, client records, medical histories, and internal company financial information have been compromised and are being made available to you.
The Newcomers Center provides immigration services aimed at supporting newcomers and creating a welcoming community. They maintain complete information about their clients in their databases, but they fail to ensure the security of this data. Due to their negligence toward their clients and employees, this data has been compromised. We offer you 380 GB of personal client data, company financial information, its current status and reporting, and human resources planning and policies.
Paragon Store Fixtures specializes in custom display cases, retail fixtures, and interior design elements for luxury stores, beauty salons, offices, restaurants, and entertainment venues. A security breach resulted in the breach of partnership agreements, resulting in the intellectual property of both the company and its clients. Internal design files were exposed, including work completed for clients in the high-end retail sector and luxury brands. Due to the company's negligence, contracts, architectural plans, and confidential design documentation became public. The identities of clients and projects have now been revealed.
CEI's mission is to produce high-quality equipment for the manufacturing industry through innovation, collaboration, and integrity. However, the company has a history of neglecting its own security, putting its customers and employees at risk. This negligence has resulted in the leakage of confidential information and personal data. We provide confidential information regarding equipment development, contracts, and customer relationships. We also have information about their subsidiaries and their entire financial structure.