Skip to content
Rhysida and Interlock Ransomware Groups Exploit Shared Malware Ecosystem

Rhysida and Interlock Ransomware Groups Exploit Shared Malware Ecosystem

First seen 16 Jun 2026, 12:49 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 17, 2026 at 12:42 UTC
  • Rhysida and Interlock ransomware groups share a malware ecosystem, including the Supper backdoor.
  • Both groups utilize initial access brokers and various downloaders to facilitate their attacks.
  • Their operations indicate a sophisticated, layered approach rather than reliance on a single malware family.

Recent analysis reveals that Rhysida and Interlock ransomware groups are interconnected through a shared ecosystem of malware tools, including the Supper backdoor. Both groups utilize initial access brokers and a variety of downloaders and crypters to stage their attacks. The research highlights that their operations rely on a layered approach rather than a single malware family, indicating a complex relationship. Interlock is linked to TAG-124 and employs various methods such as trojanized installers and traffic distribution systems for payload delivery. Rhysida's tactics include fake software download sites and signed installers, showcasing a trend towards industrialized access methods. The overlapping tools and techniques suggest shared development or a tightly knit criminal service market. This evolving threat landscape necessitates a broader detection strategy that goes beyond final encryptors to include initial access brokers and downloader infrastructure.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 91d ago How this analysis works

Timeline

2026-06-16
Rhysida and Interlock linked to malware ecosystem
Research reveals shared tools and techniques between Rhysida and Interlock, including the Supper backdoor and various downloaders.
Gbhackers
2026-06-16
Interlock tracked as Hive0163
Interlock ransomware group identified internally as Hive0163, showcasing active operations in the ransomware landscape.
Cybersecuritynews

More articles in this cluster (3)

Following this threat?

Track Interlock, KongTuke and Berserk Stealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed