mastodon.world is one of the many independent Mastodon servers you can use to participate in the fediverse.
Generic Mastodon server for anyone to use.

Server stats:

9.8K
active users

#interlock

1 post1 participant0 posts today
The New Oil<p><a href="https://mastodon.thenewoil.org/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> <a href="https://mastodon.thenewoil.org/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a> gang pushes fake <a href="https://mastodon.thenewoil.org/tags/IT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IT</span></a> tools in <a href="https://mastodon.thenewoil.org/tags/ClickFix" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ClickFix</span></a> attacks</p><p><a href="https://www.bleepingcomputer.com/news/security/interlock-ransomware-gang-pushes-fake-it-tools-in-clickfix-attacks/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/interlock-ransomware-gang-pushes-fake-it-tools-in-clickfix-attacks/</span></a></p><p><a href="https://mastodon.thenewoil.org/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a></p>
crep1x<p>Check out our new blog post by the TDR team, presenting the latest TTPs used by the <a href="https://infosec.exchange/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> ransomware group!</p><p>It includes their use of the ClickFix tactic, PyInstaller, Node.js, Cloudflare Tunnels, and new PowerShell loader/backdoor ⬇️</p><p><a href="https://infosec.exchange/@sekoia_io/114346873677895469" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@sekoia_io/11</span><span class="invisible">4346873677895469</span></a></p><p>By the way, Microsoft Threat Intelligence published an analysis yesterday on the same infection chain leveraging new PowerShell loader/backdoor (without associating it with Interlock?)</p><p><a href="https://www.microsoft.com/en-us/security/blog/2025/04/15/threat-actors-misuse-node-js-to-deliver-malware-and-other-malicious-payloads/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">microsoft.com/en-us/security/b</span><span class="invisible">log/2025/04/15/threat-actors-misuse-node-js-to-deliver-malware-and-other-malicious-payloads/</span></a></p><p>As usual, we share multiple IoCs and YARA rules in our blog post and on our community GitHub: <a href="https://github.com/SEKOIA-IO/Community/tree/main/IOCs/Interlock" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/SEKOIA-IO/Community</span><span class="invisible">/tree/main/IOCs/Interlock</span></a></p>
Sekoia.io<p>Since the apparition of the <a href="https://infosec.exchange/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> ransomware, the Sekoia <a href="https://infosec.exchange/tags/TDR" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TDR</span></a> team observed its operators evolving, improving their toolset (<a href="https://infosec.exchange/tags/LummaStealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LummaStealer</span></a> and <a href="https://infosec.exchange/tags/BerserkStealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BerserkStealer</span></a>), and leveraging new techniques such as <a href="https://infosec.exchange/tags/ClickFix" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ClickFix</span></a> to deploy the ransomware payload. </p><p><a href="https://blog.sekoia.io/interlock-ransomware-evolving-under-the-radar/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.sekoia.io/interlock-ranso</span><span class="invisible">mware-evolving-under-the-radar/</span></a></p>
RansomLook<p>New post from <a href="https://social.circl.lu/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> : Doman Building Materials Group<br>More at : <a href="https://www.ransomlook.io/group/Interlock" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">ransomlook.io/group/Interlock</span><span class="invisible"></span></a> <a href="https://social.circl.lu/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a></p>
RansomLook<p>New post from <a href="https://social.circl.lu/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> : Andretti Indoor Karting &amp; Games<br>More at : <a href="https://www.ransomlook.io/group/Interlock" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">ransomlook.io/group/Interlock</span><span class="invisible"></span></a> <a href="https://social.circl.lu/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a></p>
RansomLook<p>New post from <a href="https://social.circl.lu/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> : Drive Products<br>More at : <a href="https://www.ransomlook.io/group/Interlock" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">ransomlook.io/group/Interlock</span><span class="invisible"></span></a> <a href="https://social.circl.lu/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a></p>
RansomLook<p>New post from <a href="https://social.circl.lu/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> : Doman<br>More at : <a href="https://www.ransomlook.io/group/Interlock" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">ransomlook.io/group/Interlock</span><span class="invisible"></span></a> <a href="https://social.circl.lu/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a></p>
RansomLook<p>New post from <a href="https://social.circl.lu/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> : Cherokee County School District<br>More at : <a href="https://www.ransomlook.io/group/Interlock" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">ransomlook.io/group/Interlock</span><span class="invisible"></span></a> <a href="https://social.circl.lu/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a></p>
Pyrzout :vm:<p>Ransomware Group Takes Credit for National Presto Industries Attack – Source: www.securityweek.com <a href="https://ciso2ciso.com/ransomware-group-takes-credit-for-national-presto-industries-attack-source-www-securityweek-com/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">ciso2ciso.com/ransomware-group</span><span class="invisible">-takes-credit-for-national-presto-industries-attack-source-www-securityweek-com/</span></a> <a href="https://social.skynetcloud.site/tags/NationalPrestoIndustries" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NationalPrestoIndustries</span></a> <a href="https://social.skynetcloud.site/tags/rssfeedpostgeneratorecho" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>rssfeedpostgeneratorecho</span></a> <a href="https://social.skynetcloud.site/tags/CyberSecurityNews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurityNews</span></a> <a href="https://social.skynetcloud.site/tags/securityweekcom" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>securityweekcom</span></a> <a href="https://social.skynetcloud.site/tags/securityweek" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>securityweek</span></a> <a href="https://social.skynetcloud.site/tags/DataBreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataBreach</span></a> <a href="https://social.skynetcloud.site/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a> <a href="https://social.skynetcloud.site/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a></p>
Pyrzout :vm:<p>Ransomware Group Takes Credit for National Presto Industries Attack <a href="https://www.securityweek.com/ransomware-group-takes-credit-for-national-presto-industries-attack/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">securityweek.com/ransomware-gr</span><span class="invisible">oup-takes-credit-for-national-presto-industries-attack/</span></a> <a href="https://social.skynetcloud.site/tags/NationalPrestoIndustries" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NationalPrestoIndustries</span></a> <a href="https://social.skynetcloud.site/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a> <a href="https://social.skynetcloud.site/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://social.skynetcloud.site/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a> <a href="https://social.skynetcloud.site/tags/InterLock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InterLock</span></a></p>
Pyrzout :vm:<p>Ransomware Group Takes Credit for National Presto Industries Attack <a href="https://www.securityweek.com/ransomware-group-takes-credit-for-national-presto-industries-attack/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">securityweek.com/ransomware-gr</span><span class="invisible">oup-takes-credit-for-national-presto-industries-attack/</span></a> <a href="https://social.skynetcloud.site/tags/NationalPrestoIndustries" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NationalPrestoIndustries</span></a> <a href="https://social.skynetcloud.site/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a> <a href="https://social.skynetcloud.site/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://social.skynetcloud.site/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a> <a href="https://social.skynetcloud.site/tags/InterLock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InterLock</span></a></p>
RansomLook<p>New post from <a href="https://social.circl.lu/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> : National Defense Corp<br>More at : <a href="https://www.ransomlook.io/group/Interlock" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">ransomlook.io/group/Interlock</span><span class="invisible"></span></a> <a href="https://social.circl.lu/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a></p>
RansomLook<p>New post from <a href="https://social.circl.lu/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> : Pma<br>More at : <a href="https://www.ransomlook.io/group/Interlock" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">ransomlook.io/group/Interlock</span><span class="invisible"></span></a> <a href="https://social.circl.lu/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a></p>
RansomLook<p>New post from <a href="https://social.circl.lu/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> : General Formulations<br>More at : <a href="https://www.ransomlook.io/group/Interlock" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">ransomlook.io/group/Interlock</span><span class="invisible"></span></a> <a href="https://social.circl.lu/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a></p>
RansomLook<p>New post from <a href="https://social.circl.lu/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> : Aztec Municipal School District<br>More at : <a href="https://www.ransomlook.io/group/Interlock" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">ransomlook.io/group/Interlock</span><span class="invisible"></span></a> <a href="https://social.circl.lu/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a></p>
RansomLook<p>New post from <a href="https://social.circl.lu/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> : Milano<br>More at : <a href="https://www.ransomlook.io/group/Interlock" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">ransomlook.io/group/Interlock</span><span class="invisible"></span></a> <a href="https://social.circl.lu/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a></p>
RansomLook<p>New post from <a href="https://social.circl.lu/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> : Hancock Public School<br>More at : <a href="https://www.ransomlook.io/group/Interlock" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">ransomlook.io/group/Interlock</span><span class="invisible"></span></a> <a href="https://social.circl.lu/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a></p>
RansomLook<p>New post from <a href="https://social.circl.lu/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> : Wayne County, Michigan<br>More at : <a href="https://www.ransomlook.io/group/Interlock" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">ransomlook.io/group/Interlock</span><span class="invisible"></span></a> <a href="https://social.circl.lu/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a></p>
RansomLook<p>New post from <a href="https://social.circl.lu/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> : The Smeg Group<br>More at : <a href="https://www.ransomlook.io/group/Interlock" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">ransomlook.io/group/Interlock</span><span class="invisible"></span></a> <a href="https://social.circl.lu/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a></p>
RansomLook<p>New post from <a href="https://social.circl.lu/tags/Interlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Interlock</span></a> : The Siegel Group, Inc.<br>More at : <a href="https://www.ransomlook.io/group/Interlock" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">ransomlook.io/group/Interlock</span><span class="invisible"></span></a> <a href="https://social.circl.lu/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a></p>