[INTERLOCK] - Ransomware Victim: Community College of Beaver County - https://www.redpacketsecurity.com/interlock-ransomware-victim-community-college-of-beaver-county/
#interlock #dark_web #data_breach #OSINT #ransomware #threatintel #tor
[INTERLOCK] - Ransomware Victim: Community College of Beaver County - https://www.redpacketsecurity.com/interlock-ransomware-victim-community-college-of-beaver-county/
#interlock #dark_web #data_breach #OSINT #ransomware #threatintel #tor
[INTERLOCK] - Ransomware Victim: The Center for Hearing & Speech - https://www.redpacketsecurity.com/interlock-ransomware-victim-the-center-for-hearing-speech/
#interlock #dark_web #data_breach #OSINT #ransomware #threatintel #tor
[INTERLOCK] - Ransomware Victim: Goodwill - https://www.redpacketsecurity.com/interlock-ransomware-victim-goodwill/
#interlock #dark_web #data_breach #OSINT #ransomware #threatintel #tor
The Flow: A fake "Verify You Are Human" prompt leads to Node.js C2 (interlock RAT), followed by hands-on-keyboard activity where they use vol.exe from \AppData\Local\Temp\ to harvest credentials.
Defender Tip: Monitor for vol.exe or python.exe interacting with memory dump files in user temp folders. If you see Hashdump in your logs and it isn't your IR team... you have a live intrusion.
Want more info? Get in touch!
#CyberSecurity #Ransomware #BlueTeam #DFIR #Interlock #Infosec