Interlock is a ransomware and double-extortion threat group active since at least September 2024 and tracked by Sophos as GOLD EMBRACE. The group has targeted organizations in North America and Europe, with repeated victimization across the United States, Canada, and the United Kingdom, and a concentration on critical infrastructure, healthcare, education, government, and manufacturing-related organizations. Interlock has also been linked to attacks against municipal entities and higher-education institutions. Interlock commonly combines data theft with encryption and threatens public release of stolen information to pressure victims into paying. Reporting indicates the group operates a leak site and has published victim data after failed extortion attempts. The actor has been associated with ransomware activity affecting Windows and virtualized environments, including ESXi. The group is notable for its use of ClickFix and fake-CAPTCHA social-engineering lures for initial access, in which users are tricked into executing malicious commands through the Windows Run dialog. Observed post-compromise behavior includes deployment of remote-access tooling and custom malware such as NodeSnake, InterlockRAT, and the Supper backdoor; credential theft using legitimate memory-forensics tools including WinPmem and Volatility3; Active Directory discovery; Kerberoasting; creation of new privileged accounts; scheduled-task persistence; lateral movement to domain controllers; tampering with security tools; theft of cloud credentials; data exfiltration; and eventual ransomware deployment. Interlock has also been observed using legitimate third-party remote administration software during intrusions. The actor has demonstrated strong defense-evasion tradecraft, including obfuscated payloads, anti-analysis features, wildcarded PowerShell execution, abuse of trusted processes, and use of legitimate administrative or forensic tools to blend into victim environments. Separate reporting ties the operation to exploitation of Cisco Secure Firewall Management Center zero-day CVE-2026-20131 before public disclosure, showing that Interlock is capable of opportunistic or advanced exploitation in addition to social-engineering-led intrusions. Available reporting characterizes Interlock as a financially motivated ransomware operation rather than a state-sponsored espionage actor. Sophos has assessed that it does not appear to operate as a ransomware-as-a-service platform and instead resembles a smaller dedicated team. Known aliases and tracking names include Interlock and GOLD EMBRACE.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
More recently, Interlock has been actively exploiting CVE-2026-20131, a critical-severity zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software.
Hotta Killer (Interlock): exploits a gaming anti-cheat driver zero-day (CVE-2025-61155) to attack FortiEDR
Local privilege escalation exploit CVE-2023-36036 (JunkFiction-crypted) ... CVE CVE-2023-36036 Local privilege escalation exploit used by Interlock and ModeloRAT operators
104 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Connell Enterprises LLC.
Ransomware activity involving an Interlock ESXi decryptor; the reference discusses reverse engineering the decryptor to infer how the encryptor works.
Conducting a ransomware attack and associated data breach against AngMar Companies, with claims of exposing 710 GB of confidential information including patient data and medical records.
Referenced as a ransomware group that published employee data from the City of St. Paul after payment demands were refused.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.