ExoLock
0 incidentes
0 paises
0 sectores
ransomware RU Ultimo: -
Aliases: Interlock
ExoLock, operating under the alias Interlock, emerged in September 2024 as a financially motivated ransomware group. Unlike many contemporaries, ExoLock does not adhere to the Ransomware-as-a-Service (RaaS) model, functioning instead as a closed, dedicated collective. The group's primary objective is financial gain, often coupled with a stated intent to expose organizations' inadequate security postures. ExoLock distinguishes itself through its cross-platform ransomware capabilities, targeting Windows, Linux, and FreeBSD/ESXi environments, and its consistent use of a custom data leak site named "Worldwide Secrets Blog." The group is also known for employing the "ClickFix" social engineering technique and leveraging atypical initial access methods, such as drive-by downloads from compromised legitimate websites disguised as software updates, often exhibiting extended dwell times within compromised networks before deploying its ransomware.
Paises objetivo (SOCRadar)
United Arab Emirates
Argentina
AustraliaAruba
Brazil
CanadaCongo
Costa Rica
Germany
Spain
Sectores objetivo (SOCRadar)
Construction of BuildingsFood ManufacturingSoftware PublishersReal EstateHospitalsAccommodationAir TransportationManufacturingConstructionPublic Administration