New Interlock Ransomware Uses Fake Error Messages to Trick Windows Users
Interlock ransomware uses fake error messages and PowerShell commands to trick Windows users. Learn how this double extortion malware targets organizations in North America and Europe.

By
Content Team
Last updated:

ON THIS PAGE
Want more insights like this?
Subscribe to our newsletter to get the latest software protection strategies delivered to your inbox.
By submitting your email, you consent to Codekeeper contacting you and agree to our privacy policy.
Cybercriminals are deploying Interlock ransomware through a clever social engineering trick called ClickFix. Victims visit compromised websites that display fake error messages, prompting them to copy and run malicious PowerShell commands that appear to fix technical issues.
Active since September 2024, the ransomware has targeted organizations across North America and Europe using double extortion tactics. The malware fingerprints victim systems to identify high-value targets while avoiding security researchers. eSentire analysts discovered the sophisticated attack chain in July 2025, revealing multi-layered techniques involving PowerShell scripts and custom remote access tools.
Source: Cyber Security News

Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo