{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:19:30.126Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Interlock ransomware uses ClickFix fake CAPTCHA prompts for initial access","date":"2025-07-22","date_precision":"day","victim_org":"Multiple businesses and critical infrastructure organisations (campaign)","sector":"Healthcare","country":"Multiple","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported in the advisory.","outcomes":["Ransomware Deployment","Extortion","Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No aggregate loss figure published; the advisory notes Interlock does not state an initial ransom amount in its notes.","records_affected":null,"threat_actor":"Interlock ransomware group","summary":"A joint advisory from CISA, the FBI, HHS and MS-ISAC published on 22 July 2025 describes the Interlock ransomware group, active since late September 2024 against businesses and critical infrastructure in North America and Europe with notable impact on healthcare. The advisory documents two deception-based initial access routes: drive-by downloads from compromised legitimate websites, and the ClickFix technique in which victims are tricked into running a malicious payload by clicking a fake CAPTCHA prompt.","how_it_worked":"Visitors to compromised but otherwise legitimate websites were served a page claiming they needed to prove they were human or fix a display problem. The page silently copied a command to the clipboard and instructed the user to open the Windows Run dialog, paste and press Enter, which executed PowerShell that fetched a remote access trojan. Because the victim types the command themselves, no download prompt or macro warning appears and email gateways are entirely bypassed. Interlock operators then used the foothold for credential theft with infostealers and keyloggers, lateral movement over RDP, data exfiltration to cloud storage, and double-extortion encryption of Windows and Linux systems.","lessons":"Instrument and alert on PowerShell or mshta launched from explorer.exe via the Run dialog, and block clipboard-to-shell execution paths through application control; no legitimate CAPTCHA ever asks a user to run a command.","confidence":"Confirmed","sources":[{"title":"#StopRansomware: Interlock (AA25-203A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a","publisher":"CISA / FBI / HHS / MS-ISAC"},{"title":"#StopRansomware: Interlock (PDF)","url":"https://www.ic3.gov/CSA/2025/250722.pdf","publisher":"FBI Internet Crime Complaint Center"},{"title":"Feds Issue Interlock Ransomware Warning as Healthcare Attacks Spike","url":"https://www.hipaajournal.com/interlock-ransomware-alert-2025/","publisher":"HIPAA Journal"}],"entry_type":"campaign","slug":"2025-interlock-ransomware-uses-clickfix-fake-captcha-prompts-for-initial-acce","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-interlock-ransomware-uses-clickfix-fake-captcha-prompts-for-initial-acce"}]}