In a joint statement issued on Tuesday, the US Cybersecurity and Infrastructure Security Agency ( CISA ) and FBI are warning of increased activity by the “ Interlock ” ransomware gang , which targets businesses and critical infrastructure through sophisticated double-extortion attacks .

The advisory report, co-authored by the U.S. Department of Health and Human Services (HHS) and the Multi-State Information Sharing and Analysis Center (MS-ISAC), includes analytical indicators of breach (IOCs) from incidents that occurred up to June 2025. It also provides technical measures and best practices to defenses network
See also: UK: Ban on paying ransoms to ransomware groups – Who is affected?
Interlock: An emerging threat with a global footprint
Interlock first appeared in September 2024 and has since launched targeted attacks against organizations in various industries around the world — with the healthcare.
The group's modus operandi is based on double extortion, in which sensitive data is first extracted from victims and then their systems are encrypted. The goal is twofold: to force organizations to pay for decryption, but also to prevent data from being publicly leaked .
Notably, cybercriminals are using unusual infiltration techniques, such as drive-by downloads via compromised, seemingly legitimate websites — a rarity in the ransomware space. Additionally, their attacks include Access Trojans (RATs), such as NodeSnake, which has been detected on university networks in the UK.
Big Goals: DaVita and Kettering Health
Interlock has already claimed responsibility for major breaches at major companies, such as DaVita, a Fortune 500 multinational in the renal care sector, from which 1.5 TB of sensitive data.
See also: Decryption tool for Phobos & 8Base ransomware
Kettering Health , an organization with more than 120 medical centers and 15,000 employees, was also targeted , confirming Interlock's intention to attack critical and large infrastructure with huge impact.
New attack technique: FileFix and RATs via… Windows UI
The group also recently adopted the FileFix, a technologically advanced social engineering scenario that leverages the Windows environment — such as Windows File Explorer and HTML Applications (.HTA) — to trick users into executing malicious PowerShell or JavaScript code without any apparent security alerts.
This technique demonstrates the increasing sophistication and creativity of attackers, who target "human weakness" in combination with technological exploits.

Protection measures: Technical and educational
To protect against Interlock and other similar ransomware groups, authorities recommend a number of critical security measures:
- DNS filtering and firewall use for Internet access
- Continuous software, firmware and operating system
- Staff training in phishing and social engineering
- Network segmentation to limit damage from a potential breach
- Identity, Credential and Access Management (ICAM) policies
- Mandatory use of Multi-Factor Authentication (MFA)
Extra protection tips
- Stay up-to-date on the latest ransomware trends and tactics used by attackers
- Encryption of sensitive data
- Conducting security audits and penetration testing
- Recovery plan for rapid restoration of systems in the event of an attack
- Data backups
See also: Q2 2025: Increased ransomware attacks in retail
Defense is no longer an option — it is a necessity
The Interlock case is yet another indication of the ever-evolving nature of cyber threats. The targeting of healthcare and critical infrastructure demonstrates that cybercriminals do not hesitate to target even sectors of high societal importance. For businesses and organizations, investing in cybersecurity and cultivating a culture of digital awareness are fundamental steps to survive in the new digital age.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
