Health Sector Warned About Increasing Interlock Ransomware Attacks

Federal agencies have issued a joint alert about the Interlock ransomware group, which has increased its attacks on healthcare organizations and other critical infrastructure entities. Interlock is a financially motivated ransomware-as-a-service (RaaS) operation that recruits affiliates to conduct attacks using the Interlock encryptor and associated infrastructure. Affiliates are typically paid 70-80% of any ransom payments they generate, with the operators retaining 20%-30% of ransom payments. The group uses double extortion tactics, stealing data and encrypting files. Payment is required to obtain the keys to decrypt files and prevent stolen data from being added to the group’s data leak site.

Interlock emerged in late 2024, initially conducting a modest number of attacks; however, attacks have accelerated. The group is known to have attacked more than 50 large enterprises and critical infrastructure entities across North America and Europe, including several healthcare organizations. Known healthcare victims include DaVita, Kettering Health, and Texas Tech University Health Sciences Centers. One factor that appears to be key when targeting entities is whether they possess sensitive data, as the potential exposure of the data increases the likelihood of the ransom being paid.

Interlock most commonly gains initial access through stolen credentials purchased from initial access brokers or obtained in credential harvesting campaigns; however, the group’s tactics have evolved, and new methods of initial access have been observed. According to the joint alert from the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Health and Human Services (HHS), and the Multi-State Information Sharing and Analysis Center (MS-ISAC), Interlock has also been observed conducting ClickFix social engineering campaigns and drive-by downloads for initial access. Both are rarely seen in ransomware attacks.

ClickFix campaigns involve tricking a user into providing access to their device by executing a malicious payload under the guise of resolving an IT issue. The group also uses compromised websites for drive-by downloads, tricking users into executing a remote access trojan (RAT) under the guise of an installer for the Chrome and Edge browsers, or other popular free software solutions.

The authoring agencies provide the latest indicators of compromise (IoCs) and tactics, techniques, and procedures (TTPs) from observed attacks as late as June, and several recommended mitigations to strengthen defenses. These include cybersecurity best practices such as creating immutable, encrypted backups, securely storing those backups off-site, segmenting networks to hamper lateral movement, implementing multifactor authentication, disabling unused ports, installing antivirus software/endpoint detection solutions, and keeping software and operating systems up to date. Since social engineering and drive-by downloads are used, user education is vital to improve understanding of the ways that employees are targeted.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/