Back Gbhackers Rhysida and Interlock Ransomware Groups Linked to Initial Access Brokers and Crypter Ecosystem
Rhysida and Interlock sit inside the same ransomware supply chain, but their latest observed behavior shows a more nuanced relationship than simple code reuse.
IBM X-Force’s long-term analysis ties both groups to initial access brokers, private crypters, downloaders, and backdoors that help them stage intrusion chains before encryption.
The core finding is that both operations rely on a layered ecosystem rather than a single malware family. Interlock is associated with NodeSnake, InterlockRAT, JunkFiction downloader, Supper, and the JunkFiction crypter, while Rhysida’s recurring tooling includes Endico downloader, Broomstick, Supper, and Tomb crypter.
Initial access brokers remain the most important enabling layer in these campaigns. The report links Interlock activity to TAG-124, also tracked as LandUpdate808 and KongTuke, which has repeatedly delivered malicious payloads through ClickFix lures, trojanized installers, and traffic distribution systems.
X-Force said in a report shared with GBhackers , says the overlaps are strong enough to suggest either shared developers, shared code lineage, or a tightly connected criminal service market, but not enough to prove a single unified group.
Rhysida chains have used similar infection plumbing, including fake software download sites and signed installers, which shows how access is being industrialized rather than improvised.
The technical overlap is most visible in the malware framework itself. NodeSnake and InterlockRAT code structure, C2 conventions, and staging logic, while Supper appears to be a closely related but distinct implementation that is seen in both Interlock and Rhysida incidents.
The latest addition is the screenshot command observed in NodeJS variants, which installed the “screenshot-desktop” module via npm to take the screenshot.
On the protection side, the operators favor exclusive crypters such as JunkFiction and Tomb to conceal payloads and slow down analysis, which is a hallmark of mature ransomware tradecraft.
The infection chains are built for flexibility. Interlock ransomware campaigns have used trojanized Microsoft Teams or Edge installers, Cloudflare tunnel infrastructure, and PowerShell-based execution to drop downloader payloads and pivot into backdoors.
The crypter was observed on several different payloads including Berserk Stealer, Interlock Ransomware, Mallard Downloader, Plus Keylogger, NtlmThief, PortStarter, Supper and SystemBC.
Rhysida chains, by contrast, have leaned heavily on Tomb-crypted Broomstick and Endico, sometimes followed by Vidar or Supper for post-compromise operations and domain enumeration.
The repeated use of code-signing certificates, fake download portals, and living-off-the-land commands shows a focus on blending into normal enterprise activity.
For defenders, the main signal is that ransomware detection must extend beyond final encryptors. Access brokers, downloader infrastructure, crypters, and staging servers now form the operational backbone of both groups, which means blocking only the ransomware binary is too late.
The report also underscores that shared infrastructure and shared tooling can create misleading attribution, so hunting should prioritize behavior, infection chain, and post-exploitation tooling rather than malware labels alone.
The broader lesson is that Rhysida and Interlock are best understood as part of a common ransomware economy built on brokers, loaders, and private crypting services. Their differences matter tactically, but their similarities expose the same commercial engine underneath.
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.
Ghostwriter (UNC1151) has escalated its long-standing phishing operations by deploying convincing fake Gmail login panels…
An active campaign in which attackers are abusing Microsoft’s OAuth 2.0 Device Authorization Grant (device…
A large-scale supply chain attack targeting the popular OptinMonster WordPress plugin has exposed more than…
AI is reshaping foreign malign influence operations in subtle but consequential ways. Our analysis of…
Two new Ransomware-as-a-Service (RaaS) entrants publicly recruited affiliates, underscoring a rapid reconsolidation of the ransomware…
A sophisticated, long-running cyberespionage campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor,…
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
