First, confidential data is stolen from infected systems, then the files themselves are encrypted.
— Thus, the victim is subjected to double pressure: a ransom is demanded not only for decrypting the information, but also for keeping it from being publicly disclosed.
The Interlock group has been active relatively recently—the first attacks were recorded in September 2024.
Since then, it has expanded beyond the borders of a single country and affected organizations in various industries around the world.