SophiaX
🔍
LIVE
· New victim: Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· New victim: 3,979 new IOCs ingested in last 24h Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· 3,979 new IOCs ingested in last 24h

interlock

💰 eCrimeMotivation: financialLast active: 2026-07-31First seen: 2026-04-02
0
linked CVEs
Targeted industries
Consumer ServicesEducationHealthcareHospitality and TourismPublic SectorTransportation/Logistics
Targeted regions
CAIEPLUS
No description available.
Source: misp_galaxy · Collected: 2026-08-08
⚡ Vulnerabilities & Exploits0 CVEs
threat_actor_cve → cves / exploits.cve_ids
No CVE correlation on record for this actor yet.
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs12
domaindeadly-programming-attorneys-our.trycloudflare.com2025-07-14
domainevidence-deleted-procedure-bringing.trycloudflare.com2025-07-14
domainexisted-bunch-balance-councils.trycloudflare.com2025-07-14
domainferrari-rolling-facilities-lounge.trycloudflare.com2025-07-14
domaingalleries-physicians-psp-wv.trycloudflare.com2025-07-14
domainnowhere-locked-manor-hs.trycloudflare.com2025-07-14
domainranked-accordingly-ab-hired.trycloudflare.com2025-07-14
sha25628a9982cf2b4fc53a1545b6ed0d0c1788ca9369a847750f5652ffa0ca7f7b7d32025-07-14
sha2568afd6c0636c5d70ac0622396268786190a428635e9cf28ab23add939377727b02025-07-14
ip184.95.51.1652025-07-14
ip64.95.12.712025-07-14
urlhttp://deadly-programming-attorneys-our.trycloudflare.com2025-07-14
📰 Threat Intel Coverage1
Digest reports mentioning this actor (incl. aliases)
KongTuke FileFix Leads to New Interlock RAT Variant - The DFIR Reportmatched as Interlock2025-07-14