CVE Tools
Back to feed
Research Interlock ransomware ransomware Rhysida ransomware IBM X-Force supply-chain

Interlock and Rhysida Ransomware: IBM X-Force Maps a Shared Ecosystem

Daily CyberSecurity (securityonline.info)·By Do Son··4 min read
CVE Tools coverage

IBM X-Force published a two-year investigation into the Interlock and Rhysida ransomware ecosystem, highlighting how the two operations share multiple enabling components such as loaders, crypters, and backdoors. Interlock (tracked as Hive0163) and Rhysida (operating as RaaS since at least May 2023) reportedly show overlapping infrastructure ties, including the Supper backdoor (SocksShell or WINDYTWIST) and code similarities across families like NodeSnake, InterlockRAT, and JunkFiction. The analysis also notes exploitation of CVE-2026-20131 and CVE-2023-36036 for initial compromise and privilege escalation, underscoring why defenders should monitor the entire kill chain—not just the final ransomware payload.