Interlock

Active
Interlock is a ransomware group first observed in September 2024 that targets critical infrastructure sectors including healthcare, government, education, and technology across North America and Europe using double-extortion, with 57+ claimed victims including a major US dialysis provider exposing over two million patient records.
126 Victims
Dec 1, 2023 First Discovered
Sep 15, 2026 Last Discovered
1 Days Inactive
0% Infostealer
2/2 Sites Online
Known Locations (2)
Interlock
ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion
Interlock
ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/leaks.php
Tools Used
DefenseEvasion
ProcessHacker, ThreatFire System Monitor driver (BYOVD)
DiscoveryEnum
Advanced Port Scanner, Azure Storage Explorer
Exfiltration
AZCopy, WinSCP
LOLBAS
PsExec
Networking
PuTTY
Offsec
Cobalt Strike
RMM-Tools
AnyDesk, ScreenConnect
Intelligence
Victims (126)

Detailed victim list temporarily unavailable

This group has 126 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.