Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Threat Groups

Interlock: the drive-by ransomware crew CISA flagged

Martynas VareikisBy Martynas VareikisJuly 20, 2026Updated:July 20, 2026No Comments5 Mins Read27 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Interlock: the drive-by ransomware crew CISA flagged, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Interlock is a double-extortion ransomware operation first observed in September 2024 that earned a joint CISA, FBI, HHS and MS-ISAC advisory (AA25-203A) in July 2025 for its attacks on business and critical infrastructure across North America and Europe. What sets Interlock apart is its front door: instead of buying access or brute-forcing RDP, it lures victims through compromised legitimate websites and fake CAPTCHA prompts. The Ransomnews tracker logged 10 confirmed Interlock victims in 2026, with education, business and government most affected.

Who is Interlock?

Interlock surfaced in late September 2024 and drew a rare government spotlight within a year. The July 2025 #StopRansomware advisory documented indicators and techniques observed in FBI investigations as recently as June 2025. Interlock runs a double-extortion model, encrypting and exfiltrating data, and has built encryptors for both Windows and Linux, including variants that specifically target virtual machines. Its cross-platform reach and VM focus put it in the same bracket as the ESXi-hunting crews reshaping enterprise ransomware, and it sits alongside its peers in the Ransomnews threat-group catalogue.

What is ClickFix, and why does Interlock use it?

Interlock’s signature is social engineering that turns the victim into the delivery mechanism. Using the ClickFix technique, a user landing on a compromised or malicious page is shown a fake CAPTCHA or error and told to “fix” it by pasting a command into the Windows Run box or terminal. That command pulls down the payload. A later variant, FileFix, swaps the lure but keeps the principle: legitimate-looking activity masks a malicious action, sidestepping many endpoint and network controls. By mid-2025 the FBI tied Interlock to a PHP-based variant riding the wider KongTuke FileFix campaign.

ClickFix / FileFix delivery flow ransomnews.com Compromisedwebsite visit Fake CAPTCHA:“paste to fix” User runs cmdin Run box Payload +RAT loader Then: encrypt + exfiltrate (Windows and Linux/ESXi encryptors) The victim runs the first stage by hand, which defeats many automated controls.

How does Interlock move and encrypt?

After the initial foothold, Interlock deploys remote-access trojans and credential-stealing tooling, then moves laterally toward high-value systems. Its willingness to target virtualisation is the dangerous part: Linux and ESXi encryptors let a single well-placed action lock every virtual machine on a host, collapsing an entire datacenter’s worth of servers at once. That is the same force-multiplier logic behind the broader shift to hypervisor-level ransomware, and it is why Interlock’s cross-platform encryptors deserve attention beyond their raw victim count.

Who does Interlock hit?

Interlock spreads its targeting across business services, education, government and healthcare, with critical-infrastructure operators explicitly named in the CISA advisory. In the Ransomnews 2026 data, education is the single most-hit sector, an uncomfortable fit given how many schools and universities run legacy systems and thin security staffing. The drive-by delivery model also means Interlock’s victims are partly self-selecting: anyone whose staff browse compromised sites and follow a convincing prompt is in scope, regardless of industry.

What should defenders do?

Interlock’s reliance on user execution makes awareness a real control, not a checkbox. Teach staff that no legitimate website ever asks them to paste a command into the Run box or a terminal, and that a CAPTCHA that tells you to open PowerShell is an attack. Technically, restrict who can run scripting interpreters, log and alert on Win + R and clipboard-to-shell patterns, and deploy web filtering to cut off compromised-site traffic. Because Interlock encrypts VMs, harden and monitor your ESXi and hypervisor layer specifically, and keep those backups offline. Pair user training with EDR that catches post-execution behaviour.

Frequently asked questions

What is the Interlock ransomware CISA advisory?

AA25-203A is a July 2025 joint advisory from CISA, the FBI, HHS and MS-ISAC that documents Interlock’s indicators of compromise and techniques, based on FBI investigations through June 2025. It warns of attacks on business and critical infrastructure in North America and Europe.

How does Interlock ransomware infect systems?

Interlock uses drive-by downloads from compromised legitimate websites and the ClickFix social-engineering technique, in which a fake CAPTCHA prompts the user to paste and run a malicious command. A newer FileFix variant uses the same trick with a different lure.

Does Interlock encrypt Linux and VMware ESXi?

Yes. The FBI has observed Interlock encryptors for both Windows and Linux, and they have been seen encrypting virtual machines across both operating systems, which allows one action to lock many servers at once.

What is the difference between ClickFix and FileFix?

Both trick a user into running attacker-supplied commands under the guise of fixing an error or completing a CAPTCHA. ClickFix typically drives the user to the Run box, while FileFix, first seen widely in June 2025, uses a file-related lure and has appeared in PHP-based variants.

How do you stop ClickFix attacks?

Train users never to paste commands from a web page into the Run box or a terminal, restrict access to scripting interpreters, alert on clipboard-to-shell activity, and use web filtering to block compromised sites. User execution is the linchpin, so removing it breaks the chain.

Sources and further reading

  • CISA — #StopRansomware: Interlock (AA25-203A)
  • FBI IC3 — #StopRansomware: Interlock joint advisory (PDF)
  • Cybernews — CISA warns of Interlock targeting North America and Europe
  • Ransomnews — ESXi ransomware in 2026
  • Ransomnews live victim tracker
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleSafePay: the centralised crew that skipped affiliates
Next Article Tracing ransom payments on-chain: a 2026 OSINT walkthrough
Martynas Vareikis

Martynas Vareikis is the AI Editor at Ransomnews. He covers the intersection of artificial intelligence and information security — from machine-learning models in defensive tooling to the adversarial use of LLMs by ransomware operators, deepfake-driven social engineering, and the rise of agentic threats. His reporting focuses on translating fast-moving AI research into practical guidance for defenders, journalists, and the broader security community. Reach Martynas via [email protected].

Related Posts

SafePay: the centralised crew that skipped affiliates

July 20, 2026

INC Ransom: the RaaS that wins by mastering the basics

July 20, 2026

LockBit, 2 years after Operation Cronos: where are they now?

May 11, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.