Rhysida and Interlock Ransomware Groups Exploit Shared Malware Ecosystem

Rhysida and Interlock Ransomware Groups Exploit Shared Malware Ecosystem

First seen 16 Jun 2026, 12:49 UTC GbhackersCybersecuritynewsSocprime 80% similarity 51.9

Article Content

Browse articles
ThreatCluster

Recent analysis reveals that Rhysida and Interlock ransomware groups are interconnected through a shared ecosystem of malware tools, including the Supper backdoor. Both groups utilize initial access brokers and a variety of downloaders and crypters to stage their attacks. The research highlights that their operations rely on a layered approach rather than a single malware family, indicating a complex relationship. Interlock is linked to TAG-124 and employs various methods such as trojanized installers and traffic distribution systems for payload delivery. Rhysida's tactics include fake software download sites and signed installers, showcasing a trend towards industrialized access methods. The overlapping tools and techniques suggest shared development or a tightly knit criminal service market. This evolving threat landscape necessitates a broader detection strategy that goes beyond final encryptors to include initial access brokers and downloader infrastructure.

Key Points: • Rhysida and Interlock ransomware groups share a malware ecosystem, including the Supper backdoor. • Both groups utilize initial access brokers and various downloaders to facilitate their attacks. • Their operations indicate a sophisticated, layered approach rather than reliance on a single malware family.

ThreatCluster AI How this analysis works

Timeline

2026-06-16
Rhysida and Interlock linked to malware ecosystem
Research reveals shared tools and techniques between Rhysida and Interlock, including the Supper backdoor and various downloaders.
Gbhackers
2026-06-16
Interlock tracked as Hive0163
Interlock ransomware group identified internally as Hive0163, showcasing active operations in the ransomware landscape.
Cybersecuritynews

Community

Browse all →