Interlock and Rhysida Ransomware: IBM X-Force Maps a Shared Ecosystem
ResearchInterlock ransomwareRhysida ransomwareOur summary
IBM X-Force published a two-year investigation into the Interlock and Rhysida ransomware ecosystem, highlighting how the two operations share multiple enabling components such as loaders, crypters, and backdoors. Interlock (tracked as Hive0163) and Rhysida (operating as RaaS since at least May 2023) reportedly show overlapping infrastructure ties, including the Supper backdoor (SocksShell or WINDYTWIST) and code similarities across families like NodeSnake, InterlockRAT, and JunkFiction. The analysis also notes exploitation of CVE-2026-20131 and CVE-2023-36036 for initial compromise and privilege escalation, underscoring why defenders should monitor the entire kill chain—not just the final ransomware payload.
Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.