s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.interlock

📛 Threat Title

Malware family: Interlock

Category: Interlock First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.interlock`. Printable name: Interlock.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.interlock VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.interlock

IOC database

Type
domain
Value
elf.interlock
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.interlock

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.interlock

References (1)

Remediations (10)

  • web:cybernews.com

    The US Cybersecurity and Infrastructure Security Agency is warning businesses in North America and Europe to harden their systems against Interlock ransomware.

  • web:cybersecuritynews.com

    The newly emerged Interlock variant represents a particularly sophisticated threat, employing unconventional attack methods that set it apart from typical ransomware operations.

  • web:cyble.com

    Interlock is a stealthy, ransomware group known for targeting critical sectors with double extortion tactics. It uses fake software updates, stolen credentials, and cloud exfiltration to pressure victims into paying.

  • web:www.attackiq.com

    AttackIQ releases two attack graphs mapping Interlock ransomware TTPs and IOCs detailed in CISA Advisory AA25-203A from July 22, 2025.

  • web:www.cisa.gov

    Prevent initial access by implementing domain name system (DNS) filtering and web access firewalls, and training users to spot social engineering attempts. Mitigate known vulnerabilities by ensuring operating systems, software, and firmware are patched and up to date. Segment networks to restrict lateral movement from initial infected devices and other devices in the same organization ...

  • web:www.csoonline.com

    A new joint advisory by the FBI, HHS, and CISA reveals how Interlock's psychological manipulation and rare entry vectors like drive-by downloads and fake system fixes are reshaping ransomware ...

  • web:www.fortinet.com

    An in-depth analysis of an Interlock ransomware intrusion, detailing new malware tooling, defense evasion techniques, and high-ROI detection strategies.

  • web:www.helpnetsecurity.com

    A Cisco Secure FMC flaw (CVE-2026-20131) patched in early March 2026 has been exploited as a zero-day by the Interlock ransomware gang.

  • web:www.ic3.gov

    Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Interlock Ransomware Activity Prevent initial access by implementing domain name system (DNS) filtering and web access firewalls, and training users to spot social engineering attempts.

  • web:www.picussecurity.com

    Interlock ransomware targets critical infrastructure using drive-by downloads, ClickFix social engineering, and double extortion. In this blog post, Picus explains the TTPs of the Interlock group in detail.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.