Skip to content

— Interlock

Threat-actor battle card · maintained from public sources · last updated 2026-09-02 · also known as Nefarious Mantis

CategoryRansomware
AttributionUnknown (financially motivated; no confirmed state sponsorship)
First seen2024-09
StatusActive
Primary targetsHealthcare, Education, Government, Manufacturing, Technology, Business Services, Critical infrastructure (North America and Europe)

Overview

Interlock (also tracked as Nefarious Mantis) is a financially motivated ransomware group active since September 2024, operating a double-extortion model across critical infrastructure sectors in North America and Europe. It attracted a CISA/FBI joint advisory (AA25-203A, July 2025) after escalating attacks against healthcare, manufacturing, and government targets. Interlock is unusual among ransomware families for developing a FreeBSD/Linux ELF encryptor in addition to its Windows payload — enabling it to hit VMware ESXi hosts and BSD-based network appliances that most Windows-only tools miss.

As of September 2, 2026, Interlock's total victim count across all tracked sources stands at 130+ named victims, with sector concentration in Education (27+), Manufacturing (17+), Business Services (15+), Public Sector (14+), and Healthcare (13+). Geographic distribution broadly consistent with prior tracking: US (majority), Canada, UK, Australia, Italy. The group was last observed active August 31. Average dwell/delay period approximately 58.9 days between intrusion and DLS publication. Most recent confirmed DLS posting: Converting Equipment International (UK manufacturing, attack date July 16 2026).

Tradecraft

  • Initial access: Drive-by downloads from compromised legitimate websites; ClickFix social-engineering lures that trick users into pasting and running malicious PowerShell; fake browser update pages.
  • Remote access tools: RemCom (remote shell), AnyDesk, WinSCP, PuTTY — all legitimate software used to blend with normal IT traffic.
  • Tunneling: Ligolo-ng for encrypted C2 over TLS.
  • Memory forensics tools (August 2026 addition): Volatility3 (open-source memory analysis) and WinPmem (kernel-level memory acquisition) — new to the toolkit as of August 2026, per Fortinet FortiGuard Labs and Broadcom reporting.
  • Encryptors: Dual-payload architecture — Windows PE and a FreeBSD/Linux ELF binary — each signed with self-signed certificates. The FreeBSD/Linux variant allows encryption of ESXi hosts and BSD-based appliances that Windows-only tools miss.
  • Extortion: DLS ("Worldwide Secrets Blog" on TOR); combines data publication threat with decryption ransom; sets short deadlines.
  • Vulnerability exploitation: Confirmed pre-disclosure exploitation of at least two Cisco Secure Firewall Management Center zero-days — the first approximately 36 days before Cisco's public disclosure, a second (CVE-2026-20131) approximately two weeks before acknowledgement (August 2026). Has also leveraged Amazon enterprise firewall flaws per AWS Security findings. This pattern of repeated pre-disclosure zero-day exploitation marks Interlock as operating well above commodity RaaS capability.

Notable victims

  • Reynella East College (education/South Australia) — all IT systems offline; 1,900+ students and staff at risk; school disclosed breach June 9, 2026; Interlock DLS claim June 23, 2026. Cyber Daily
  • Clearview Eye Centre (healthcare/ophthalmology/Calgary, Canada) — Interlock DLS claim June 25-26, 2026; patient medical records and financial data alleged; data scope unconfirmed; no Clearview public statement — 🟥 unverified. DeXpose
  • Converting Equipment International (manufacturing/UK) — attack date July 16 2026; data published to "Worldwide Secrets Blog" DLS late July 2026 — 🟥 unverified DLS claim; no corporate statement. SOCRadar

Assessment

Interlock's FreeBSD encryptor, repeated pre-disclosure Cisco FMC zero-day exploitation, and August 2026 addition of Volatility3/WinPmem memory-forensics tools all signal sustained capability investment well beyond commodity RaaS tooling. The CISA/FBI advisory (AA25-203A, July 2025) marks it as a persistent threat to healthcare and government networks. With 130+ victims as of September 2026 and confirmed healthcare, education, and ophthalmology targeting across North America, UK, and Australia, practitioners in those sectors should treat Interlock as an active and escalating threat. The ClickFix initial access vector remains effective across its target verticals — organisations relying on end-user awareness as the primary ClickFix defence should assume exposure. Cisco FMC administrators must treat pre-disclosure exploitation of CVE-2026-20131 and its predecessor as confirmed and patch immediately; all FMC instances should have network segmentation enforced between the management plane and production. IBM X-Force and Arctic Wolf flag Interlock as a priority tracking target through H2 2026. The addition of memory-forensics tooling suggests the group is investigating in-memory credential harvesting to sustain access in EDR-rich environments.

Sources

🗂️ Attacks & victims

All disclosed victims attributed to this actor, newest first.

July 2026

Jul 31 Southeastern Oklahoma State University Interlock Ransomware · Education · USA Interlock ransomware attack on public university in Durant OK; confidential financial records including unaudited earnings reports and tax files stolen; campus closed 3 days; 42,000 students locked out; DLS claim posted Aug 19 2026 · Sources: https://www.kxii.com/video/2026/08/03/southeastern-oklahoma-state-university-reopen-tuesday-after-cybersecurity-incident/
Jul 16 Converting Equipment International Interlock Ransomware · Manufacturing · GB UK-based manufacturing company (converting equipment). Attack date July 16 2026; DLS posting July 2026. Data leaked to Interlock's Worldwide Secrets Blog. · Sources: https://socradar.io/free-tools/ransomware-intelligence/victims/converting-equipment-international-interlock-bc57bbfc
Jul 07 YMCA of Western North Carolina Interlock Ransomware · non-profit · community services/US Interlock DLS claim July 7, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/interlock · Sources: [ransomware.live]

June 2026

Jun 26 Clearview Eye Centre Interlock Ransomware · healthcare · ophthalmology/Canada ophthalmic clinic and eye care centre; Interlock DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/interlock · https://www.dexpose.io/interlock-ransomware-attack-on-clearview-eye-centre/ · Sources: [ransomware.live] · [DeXpose]
Jun 23 Reynella East College Interlock Ransomware · education · Australia all IT systems offline; 1,900+ students and staff at risk; school disclosed breach June 9 in letter to parents; Interlock DLS claim posted June 23; investigation ongoing, data exposure unconfirmed · https://www.cyberdaily.au/security/13731-parents-warned-after-cyber-security-breach-at-south-australia-s-reynella-east-college · https://www.ransomware.live/ · Sources: [Cyber Daily] · [ransomware.live]

← All threat actors · Full victim database →