EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Ransomware

#StopRansomware: Interlock

Fonte ufficiale
Sintesi operativa EudorIA

Cosa significa

Priorità 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware #StopRansomware: Interlock. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Perché conta

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Benefici operativi potenziali

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indicazioni da confermare sul perimetro tecnico e organizzativo del cliente.
Controlli pertinentiVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
DestinatariITSOCCISOManagement
Centro informazioni

Traduzione in elaborazione

CISA

Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.

Testo acquisito dalla fonte

Cybersecurity Advisory #StopRansomware: Interlock Release Date July 22, 2025 Alert Code aa25-203a CISA Product Feedback Survey Related topics: Malware, Phishing, and Ransomware , Cyber Threats and Response Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Interlock Ransomware Activity Prevent initial access by implementing domain name system (DNS) filtering and web access firewalls, and training users to spot social engineering attempts. Mitigate known vulnerabilities by ensuring operating systems, software, and firmware are patched and up to date. Segment networks to restrict lateral movement from initial infected devices and other devices in the same organization. Implement identity, credential, and access management (ICAM) policies across the organization and then require multifactor authentication (MFA) for all services to the extent possible. Summary Note : This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources. The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Department of Health and Human Services (HHS), and Multi-State Information Sharing and Analysis Center (MS-ISAC)—hereafter referred to as “the authoring organizations”—are releasing this joint advisory to disseminate known Interlock ransomware IOCs and TTPs identif

Indicatori CISA verificabili

26 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Ultima verifica: 2026-09-25T23:35:31.503319+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
SHA-13703374c9622f74edc9c8e3a47a5d53007f7721e
SHA-1b625cc9e4024d09084e80a4a42ab7ccaa6afb61d
SHA-1514946a8fc248de1ccf0dbeee2108a3b4d75b5f6
SHA-256c733d85f445004c9d6918f7c09a1e0d38a8f3b37ad825cd544b865dba36a1ba6
SHA-25688f26f3721076f74996f8518469d98bf9be0eaee5b9eccc72867ebfc25ea4e83
SHA-25668a49d5a097e3850f3bb572baf2b75a8e158dadb70baddc205c2628a9b660e7a
SHA-25696babe53d6569ee3b4d8fc09c2a6557e49ebc2ed1b965abda0f7f51378557eb1
SHA-256a70af759e38219ca3a7f7645f3e103b13c9fb1db6d13b68f3d468b7987540ddf
SHA-25644887125aa2df864226421ee694d51e5535d8c6f70e327e9bcb366e43fd892c1
SHA-256fba4883bf4f73aa48a957d894051d78e0085ecc3170b1ff50e61ccec6aeee2cd
SHA-25670ee22d394e107fbb807d86d187c216ad66b8537edc67931559a8aef18f6b5b3
SHA-2567b9e12e3561285181634ab32015eb653ab5e5cfa157dd16cdd327104b258c332
MD5d6e991dcdd91323d979878025f0ceaea
SHA-161d585e0b849f2594d6aa1d7af1c44fdedc3c985
SHA-2561d04e33009bcd017898b9e1387e40b5c04279c02ebc110f12e4a724ccdb9e4fb
SSDEEP768:op9NMxxwKIWUi4OCuwmO4kuGjmHx/3rYLTwKnLQvacb1PSFhpyR4e3+knmPg5jtt:tBIjO8uvHufH4acghed+kneg5jtw4G27
SHA-25670bb799557da5ac4f18093decc60c96c13359e30f246683815a512d7f9824c8f
SHA-25694bf0aba5f9f32b9c35e8dfc70afd8a35621ed6ef084453dc1b10719ae72f8e2
SHA-256dfb5ba578b81f05593c047f2c822eeb03785aecffb1504dcb7f8357e898b5024
SHA-256f51b3d054995803d04a754ea3ff7d31823fab654393e8054b227092580be43db
MD5edbf152ed9ac79e5d9e0111d1071af48
SHA-1b0cfa2089802634ffb8c77962cdb18317a6332d4
SHA-25664a0ab00d90682b1807c5d7da1a4ae67cde4c5757fc7d995d8f126f0ec8ae983
SSDEEP24576:DN79qK/icab2YQqQOFkjHCOS1s4YlD/40vWcPAmYNuiq3XnH1:p79t/fab2N6yHWHYHvzPAmY2Hn
SHA-256ff7ad2376ae01e4b3f1e1d7ae630f87b8262b5c11bc5d953e1ac34ffe81401b5
SHA-256c20baba26ebb596de14b403b9f78ddc3c13ce9870eea332476ac2c1dd582aa07

Provenienza

Allegato ufficiale CISA · 2025-07-17T15:14:08Z

SHA-512: 5426f804cc0151a3eeefb6b5aa845b0c8ba9f6610941ce3bd57ad3ea6d145208359eff9d8ffd662bc9738076370b35921136b9b92b196c10a795af4ec59308f2

Fonte
CISA Cybersecurity Advisories
Entità pubblicatrice
CISA
Tipo entità
Autorità nazionale
Area
North America · US
Lingua originale
en · traduzione in preparazione
Pubblicazione
22/07/2025 14:00
Condivisione
TLP:CLEAR
MITRE ATT&CK
T1007, T1016, T1021.001, T1033, T1036.005, T1048, T1056, T1056.001, T1059.001, T1070.004, T1078, T1078.002, T1082, T1105, T1189, T1204.004, T1218.011, T1219, T1486, T1530, T1547.001, T1555.003, T1558.003, T1567.002, T1657
Classificazione
Critica
Gruppo attribuito dalla fonte
Interlock
Paese indicato
US

Azione indicata dalla fonte

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Riferimenti tecnici ufficiali

Apri la fonte originale