Back to Intelligence

INTERLOCK Ransomware Gang: 2 New Leak-Site Claims — US Professional Services Targeting Analysis & Detection Rules

SA
Security Arsenal Team
September 30, 2026
13 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-01 | Source: ransomware.live leak-site monitoring | Nature of data: Unverified threat-actor claims

Executive Summary

On 2026-09-29 and 2026-09-30, the INTERLOCK ransomware gang published two new victim claims on its dark web leak site, both targeting organizations in the United States. The named organizations are Blaise C. Bender, PC (Professional Services) and Tekko Enterprises, Inc (sector not classified in source data). Both postings were independently observed by two separate leak-site crawlers, which confirms that the gang did publish these claims — it does not confirm that any breach occurred.

This activity is consistent with INTERLOCK's established playbook: opportunistic initial access via social engineering (notably ClickFix-style fake update lures), deployment of a Node.js-based remote access tool, data theft, and then double-extortion pressure with public listing deadlines. Enterprise defenders in professional services and adjacent US sectors should treat this window as elevated-risk and validate the controls and detections in this briefing.

Sourcing & Verification

  • 2 of 2 listings in this briefing were independently observed by a second leak-site crawler (MULTI-SOURCE tier). 0 listings appear on a single source only.
  • Inclusion on INTERLOCK's leak site reflects the threat actor's claim and is not confirmation of a breach. No corroboration tier in our data confirms a compromise — only the named organization or its regulator can do that.
  • A named organization may dispute a listing, and a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction and incident type, and not every incident is reportable. Neither silence nor denial settles the question.
  • Security Arsenal will publish corrections to this briefing if warranted, and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — INTERLOCK

INTERLOCK is a ransomware operation first observed in late September 2024 that quickly distinguished itself through aggressive targeting of US organizations and a technically unusual toolkit.

  • Aliases / branding: INTERLOCK (leak site branded "Worldwide Secrets Blog"). Some reporting associates tooling overlap with the broader Rhysida-affiliated ecosystem, though INTERLOCK operates as its own brand.
  • Operating model: Closed or semi-private group rather than an open Ransomware-as-a-Service marketplace. Recruitment of a small affiliate set has been suggested but it does not run a public affiliate program like LockBit or RansomHub.
  • Initial access methods:
    • ClickFix-style social engineering — fake browser update and fake CAPTCHA prompts that trick users into pasting and executing malicious PowerShell commands. This is the gang's signature initial access tradecraft.
    • Compromised legitimate sites hosting the lure payloads, improving lure credibility.
    • Opportunistic exploitation of internet-facing services (VPN gateways, exposed RDP) consistent with the KEV-listed vulnerabilities discussed below.
  • Tooling: Node.js-based remote access trojan commonly tracked as NodeSnake; heavy use of native utilities for staging; AzCopy observed for bulk data exfiltration to attacker-controlled Azure Blob storage; a rare FreeBSD-targeting encryptor variant in addition to the Windows encryptor.
  • Extortion model: Double extortion. Data is exfiltrated before encryption; victims are listed on the leak site with countdown timers when negotiations stall.
  • Ransom demands: Variable, scaling with victim revenue — reported demands range from the low six figures to multi-million dollars for larger targets. No fixed demand template is published.
  • Dwell time: Observed dwell time before detonation typically ranges from several days to a few weeks, with data theft and staging often compressed into the final 24–72 hours before encryption.

Current Campaign Analysis

Sectors and Victim Profile

The two late-September claims cover:

  • Blaise C. Bender, PC — Professional Services, US (claimed 2026-09-30)
  • Tekko Enterprises, Inc — sector not classified in source data, US (claimed 2026-09-29)

With only two postings in the last 100 monitored entries, no strong sector cluster can be asserted. The professional services listing is consistent with INTERLOCK's historical appetite for small-to-mid-size US professional firms (legal, accounting, financial services), which typically hold sensitive third-party client data — highly leverageable for extortion — while often running lean IT teams with limited detection coverage. Based on this victim class, revenue estimates for typical targets in this profile fall broadly in the $1M–$50M range, though Tekko Enterprises, Inc cannot be reliably sized from available data.

Geographic Concentration

100% of current listings are US-based. This matches INTERLOCK's sustained US focus since emergence.

Posting Frequency and Escalation

Two postings across 2026-09-29 and 2026-09-30 suggest a short burst of leak-site activity after a quieter period, consistent with either a completed intrusion pipeline reaching the extortion stage or a deliberate batching of listings to generate pressure. Defenders should watch for follow-on listings in the next 7–14 days, which would indicate a broader campaign wave rather than isolated claims.

CVE Exposure Hypothesis

We have no evidence linking a specific CVE to the initial access vector for either named organization. However, at the sector level, several vulnerabilities currently in CISA's Known Exploited Vulnerabilities catalog — all flagged with confirmed ransomware use — map to the exposure profile INTERLOCK exploits:

  • CVE-2026-50751 (Check Point Security Gateway, improper authentication in IKEv1) — perimeter VPN access, matching the gang's observed interest in edge devices.
  • CVE-2026-20316 (Cisco Secure Firewall Management Center, hard-coded password) — management-plane takeover of network security infrastructure.
  • CVE-2026-59310 (VMware vCenter path traversal) — virtualization-plane compromise, relevant to INTERLOCK's practice of encrypting ESXi-hosted workloads for maximum impact.
  • CVE-2026-63077 (JetBrains TeamCity deserialization) and CVE-2026-48027 (Nx Console embedded malicious code) — build/CI supply-chain exposure consistent with the gang's social-engineering-plus-supply-chain blend.

Treat these as hypothesis-level exposure to prioritize in patching, not as confirmed intrusion paths for the named listings.

Detection Engineering

The following detections target INTERLOCK's documented TTPs: ClickFix-driven PowerShell execution, NodeSnake RAT staging, AzCopy-based exfiltration, and pre-encryption staging. Deploy in validation mode first; tune for your environment.

YAML
---
title: ClickFix-Style User-Driven PowerShell Execution via Run Dialog or Clipboard
description: Detects ClickFix fake-update/CAPTCHA lures where users paste encoded or LOLBin-invoking PowerShell commands, a signature INTERLOCK initial access technique.
status: experimental
date: 2026/10/01
author: Security Arsenal Threat Research
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        Image|endswith:
            - '\powershell.exe'
            - '\powershell_ise.exe'
            - '\pwsh.exe'
            - '\mshta.exe'
            - '\rundll32.exe'
    selection_cmd:
        CommandLine|contains:
            - 'iex('
            - 'Invoke-Expression'
            - 'IEX '
            - 'FromBase64String'
            - ' -enc '
            - ' -e '
            - 'Invoke-WebRequest'
            - 'iwr '
            - 'DownloadString'
    filter_explorer_parent:
        ParentImage|endswith:
            - '\msedge.exe'
            - '\chrome.exe'
            - '\firefox.exe'
        CommandLine|contains: 'UpdateSession'  # placeholder benign pattern; tune per environment
    condition: selection_img and selection_cmd and not filter_explorer_parent
fields:
    - Image
    - CommandLine
    - ParentImage
    - User
falsepositives:
    - Legitimate admin scripts; software deployment tooling
level: high
tags:
    - attack.t1204
    - attack.t1059.001
---
title: AzCopy Execution with Blob Exfiltration Indicators
description: Detects AzCopy invocation for bulk file transfer to Azure Blob endpoints, a documented INTERLOCK pre-encryption data theft method.
status: experimental
date: 2026/10/01
author: Security Arsenal Threat Research
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        Image|endswith: '\azcopy.exe'
    selection_cmd:
        CommandLine|contains:
            - ' copy '
            - 'blob.core.windows.net'
            - '?sv='
            - '--output-level'
    filter_approved_path:
        Image|startswith:
            - 'C:\Program Files\Microsoft\AzCopy'
            - 'C:\approved-tooling\'  # tune to sanctioned AzCopy paths
    condition: selection_img and selection_cmd and not filter_approved_path
fields:
    - Image
    - CommandLine
    - ParentImage
    - User
falsepositives:
    - Sanctioned backup/migration jobs using AzCopy; whitelist by path and service account
level: high
tags:
    - attack.t1567.002
    - attack.t1105
---
title: Node.js Runtime Spawning Suspicious Child Processes - NodeSnake RAT Pattern
description: Detects node.exe executing scripts from non-standard directories and spawning shell or discovery commands, consistent with INTERLOCK's NodeSnake remote access tooling.
status: experimental
date: 2026/10/01
author: Security Arsenal Threat Research
logsource:
    category: process_creation
    product: windows
detection:
    selection_parent:
        ParentImage|endswith: '\node.exe'
    selection_child:
        Image|endswith:
            - '\cmd.exe'
            - '\powershell.exe'
            - '\net.exe'
            - '\whoami.exe'
            - '\ipconfig.exe'
            - '\nltest.exe'
            - '\vssadmin.exe'
    selection_node_path:
        ParentCommandLine|contains:
            - '\AppData\'
            - '\Temp\'
            - '\Users\Public\'
            - '\ProgramData\'
    condition: selection_parent and selection_child and selection_node_path
fields:
    - ParentImage
    - ParentCommandLine
    - Image
    - CommandLine
    - User
falsepositives:
    - Legitimate Node.js development or build agents; exclude known developer workstations
level: high
tags:
    - attack.t1059.007
    - attack.t1059
    - attack.t1033

The following KQL query hunts for pre-ransomware staging and lateral movement patterns associated with INTERLOCK's playbook in Microsoft Sentinel: shadow copy deletion, archive staging, remote service creation (PsExec-style), and WMI remote execution clustered on a single host within a short window.

KQL — Microsoft Sentinel / Defender
// INTERLOCK pre-encryption staging & lateral movement hunt
// Window: 7 days. Clusters suspicious events per device per hour.
let lookback = 7d;
let staging =
    DeviceProcessEvents
    | where TimeGenerated > ago(lookback)
    | extend Cmd = tolower(ProcessCommandLine)
    | extend Indicator = case(
        Cmd has "vssadmin" and Cmd has "delete shadows", "ShadowCopyDelete",
        Cmd has "bcdedit" and Cmd has "recoveryenabled", "BootRecoveryDisable",
        Cmd has "wmic" and Cmd has "shadowcopy" and Cmd has "delete", "ShadowCopyDelete",
        FileName =~ "rar.exe" or FileName =~ "7z.exe" or Cmd has ".rar" or Cmd has "a -m", "ArchiveStaging",
        FileName =~ "azcopy.exe" or Cmd has "blob.core.windows.net", "AzCopyExfil",
        Cmd has "psexec" or Cmd has "\\\\" and Cmd has "admin$", "PsExecStyleRemote",
        Cmd has "wmic" and Cmd has "/node:", "WMIRemote",
        FileName =~ "node.exe" and (FolderPath has @"\AppData\" or FolderPath has @"\Users\Public\"), "NodeSnakePattern",
        "")
    | where Indicator != ""
    | summarize Indicators = make_set(Indicator), Commands = make_set(ProcessCommandLine, 5), EventCount = count()
        by DeviceName, AccountName, bin(TimeGenerated, 1h)
    | extend IndicatorCount = array_length(Indicators);
staging
| where IndicatorCount >= 2 or EventCount >= 5
| project TimeGenerated, DeviceName, AccountName, IndicatorCount, Indicators, EventCount, Commands
| order by IndicatorCount desc;

The following PowerShell script performs rapid-response checks on a Windows host: RDP exposure, scheduled tasks created in the last 7 days, shadow copy state, and recently created executables in staging directories commonly abused by INTERLOCK.

PowerShell
# rapid-interlock-triage.ps1 - Security Arsenal IR rapid triage
# Run elevated. Read-only; safe to execute on production hosts.

Write-Host "=== INTERLOCK Rapid Triage ===" -ForegroundColor Cyan

# 1. RDP exposure check
$rdp = Get-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue
$rdpEnabled = ($rdp.fDenyTSConnections -eq 0)
Write-Host "[*] RDP enabled: $rdpEnabled"
Get-NetTCPConnection -State Listen -ErrorAction SilentlyContinue |
    Where-Object { $_.LocalPort -in 3389, 5985, 5986, 22 } |
    Select-Object LocalAddress, LocalPort, OwningProcess |
    Format-Table -AutoSize

# 2. Scheduled tasks created in the last 7 days
Write-Host "[*] Scheduled tasks created in last 7 days:"
Get-ScheduledTask | Where-Object {
    $_.Date -and ([datetime]$_.Date) -gt (Get-Date).AddDays(-7)
} | Select-Object TaskName, TaskPath, Date | Format-Table -AutoSize

# 3. Volume Shadow Copies
Write-Host "[*] Shadow copies present:"
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if ($shadows) { $shadows | Select-Object ID, InstallDate, VolumeName | Format-Table -AutoSize }
else { Write-Host "    [!] NO shadow copies found - possible vssadmin deletion (encryption precursor)" -ForegroundColor Red }

# 4. Recent executables/scripts in common staging dirs (last 7 days)
Write-Host "[*] Recent executables in staging directories:"
$dirs = @("$env:TEMP", "C:\Users\Public", "C:\ProgramData", "$env:APPDATA")
foreach ($d in $dirs) {
    Get-ChildItem -Path $d -Recurse -Include *.exe,*.ps1,*.js,*.bat,*.dll -ErrorAction SilentlyContinue |
        Where-Object { $_.CreationTime -gt (Get-Date).AddDays(-7) } |
        Select-Object FullName, CreationTime, Length
}

# 5. AzCopy / node.exe presence check
Write-Host "[*] Tooling indicators (azcopy/node in non-standard paths):"
Get-ChildItem -Path "C:\" -Recurse -Include azcopy.exe,node.exe -ErrorAction SilentlyContinue -Depth 4 |
    Where-Object { $_.FullName -notmatch 'nodejs|Program Files' } |
    Select-Object FullName | Format-Table -AutoSize

Write-Host "=== Triage complete. Correlate any hits with Sigma/KQL findings. ===" -ForegroundColor Cyan

Incident Response Priorities

T-Minus Detection Checklist (before encryption fires)

  1. ClickFix lure execution — PowerShell/mshta spawned by a browser or launched from the Run dialog with encoded or download-cradle commands.
  2. NodeSnake presence — node.exe running from %APPDATA%, %TEMP%, or C:\Users\Public spawning discovery commands (whoami, nltest, ipconfig /all).
  3. Data staging — unexpected rar.exe/7z.exe archive creation of large directories, especially on file servers or admin workstations.
  4. AzCopy exfiltration — any azcopy.exe execution outside sanctioned backup tooling; outbound transfer spikes to *.blob.core.windows.net.
  5. Defense evasion — vssadmin delete shadows, bcdedit ... recoveryenabled no, mass deletion of event logs, or disabling of EDR services.
  6. Lateral movement burst — PsExec-style remote service installs (Event 7045 with random service names), WMI /node: execution, admin$ writes across multiple hosts within hours.

Critical Assets This Gang Prioritizes for Exfiltration

  • Client-sensitive records held by professional services firms (legal files, financial data, PII).
  • File servers and NAS shares with broadly-mapped drive access.
  • Email and document repositories of executives and legal/finance staff.
  • Backup catalogs and credentials that enable destruction of recovery options.

Containment Actions Ordered by Urgency

  1. Isolate any host showing staging/exfil indicators from the network (EDR network isolation first; VLAN quarantine second).
  2. Block azcopy.exe and node.exe execution outside sanctioned paths via AppLocker/WDAC and force-block outbound to unapproved Azure Blob endpoints at the proxy.
  3. Reset credentials for any account observed in lateral movement events, starting with privileged and service accounts; assume Kerberos tickets are compromised on affected hosts.
  4. Preserve volatile evidence (process lists, network connections, memory on patient-zero host) before rebooting or imaging.
  5. Verify backup integrity and confirm offline/immutable copies exist before engaging recovery — INTERLOCK's playbook includes targeting backup infrastructure.
  6. Engage external IR counsel early; leak-site listing creates disclosure-clock pressure even when the underlying claim is unverified.

Hardening Recommendations

Immediate (24 hours)

  • Block ClickFix execution paths: deploy ASR rules or AppLocker policies blocking child processes of browsers and Office apps (PowerShell, mshta, rundll32). Disable Win+R paste-execution risk through user awareness on fake CAPTCHA/update lures — INTERLOCK's primary lure family.
  • Patch KEV perimeter items: prioritize CVE-2026-50751 (Check Point), CVE-2026-20316 (Cisco FMC), CVE-2026-59310 (vCenter), CVE-2026-63077 (TeamCity), and CVE-2026-48027 (Nx Console) per CISA KEV deadlines.
  • Restrict AzCopy: block or alert on azcopy.exe outside approved deployment paths; proxy-block unapproved *.blob.core.windows.net destinations.
  • Audit RDP/VPN exposure: confirm no direct internet-facing RDP; enforce MFA on all remote access gateways; review VPN logs for anomalous IKEv1 behavior on Check Point gateways.
  • Verify shadow copies and offline backups on critical servers now, not during an incident.

Short-Term (2 weeks)

  • Segmentation: isolate virtualization management (vCenter/ESXi), backup infrastructure, and file servers into controlled enclaves with allow-listed administrative paths; INTERLOCK's FreeBSD encryptor targets virtualization hosts, so ESXi management plane isolation is high-value.
  • Application control baseline: WDAC/AppLocker across servers blocking unsigned Node.js, script hosts, and archive utilities outside approved locations.
  • Detection deployment: onboard the Sigma and KQL content in this briefing into your SIEM/SOC; build a standing hunt for staging indicators (archive + shadow deletion + remote service creation clustered per host).
  • CI/CD supply-chain review: audit TeamCity and Nx tooling exposure, pin dependencies, and enforce signed builds in response to the KEV-listed developer-tool vulnerabilities.
  • Tabletop exercise: run a double-extortion scenario including leak-site notification handling, legal disclosure decision-making, and client-notification workflows for professional services data.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.