Gbhackers Rhysida and Interlock Ransomware Groups Exploit Shared Malware Ecosystem
Article Content
- •Rhysida and Interlock ransomware groups share a malware ecosystem, including the Supper backdoor.
- •Both groups utilize initial access brokers and various downloaders to facilitate their attacks.
- •Their operations indicate a sophisticated, layered approach rather than reliance on a single malware family.
Recent analysis reveals that Rhysida and Interlock ransomware groups are interconnected through a shared ecosystem of malware tools, including the Supper backdoor. Both groups utilize initial access brokers and a variety of downloaders and crypters to stage their attacks. The research highlights that their operations rely on a layered approach rather than a single malware family, indicating a complex relationship. Interlock is linked to TAG-124 and employs various methods such as trojanized installers and traffic distribution systems for payload delivery. Rhysida's tactics include fake software download sites and signed installers, showcasing a trend towards industrialized access methods. The overlapping tools and techniques suggest shared development or a tightly knit criminal service market. This evolving threat landscape necessitates a broader detection strategy that goes beyond final encryptors to include initial access brokers and downloader infrastructure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Interlock, KongTuke and Berserk Stealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…
Multiple Ransomware Attacks Target Various Companies on September 7, 2026 On September 7, 2026, multiple companies fell victim to ransomware attacks from various groups, including AURORA, THEGENTLEMEN, and DARK PROJECT. Notable victims include Jinny Beauty Supply, Zanini, and NFM Lending, with claims of extensive data breaches involving sensitive customer and corporate information. The…