Uptime Hamster: 11d 8h 46mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza ExoLock

ExoLock

0 incidentes 0 paises 0 sectores ransomware RU Ultimo: -
Aliases: Interlock
Ver en IntelTracker → APTTrail →
ExoLock, operating under the alias Interlock, emerged in September 2024 as a financially motivated ransomware group. Unlike many contemporaries, ExoLock does not adhere to the Ransomware-as-a-Service (RaaS) model, functioning instead as a closed, dedicated collective. The group's primary objective is financial gain, often coupled with a stated intent to expose organizations' inadequate security postures. ExoLock distinguishes itself through its cross-platform ransomware capabilities, targeting Windows, Linux, and FreeBSD/ESXi environments, and its consistent use of a custom data leak site named "Worldwide Secrets Blog." The group is also known for employing the "ClickFix" social engineering technique and leveraging atypical initial access methods, such as drive-by downloads from compromised legitimate websites disguised as software updates, often exhibiting extended dwell times within compromised networks before deploying its ransomware.

Aliases del actor

Interlock

Actores similares

interlockransomware · 33
Tipo
ransomware
Pais origen
RU
Motivacion
-
Impacto
57
Actualizado
Fri, 19 Ju

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAustraliaArubaBrazilCanadaCongoCosta RicaGermanySpain

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingSoftware PublishersReal EstateHospitalsAccommodationAir TransportationManufacturingConstructionPublic Administration