Interlock is a ransomware family operated by the eponymous cybercriminal group, tracked by Sophos as GOLD EMBRACE and active since September 2024. It targets Windows, Linux, and VMware ESXi environments. The operation combines file and virtual-machine disk encryption with data theft, demanding payment and threatening publication of stolen information. Victims include healthcare providers, educational institutions, government bodies, manufacturers, and other critical-infrastructure organizations, particularly in North America and Europe.
Interlock intrusion chains use compromised legitimate websites, counterfeit software updates, and ClickFix social engineering. Fake CAPTCHA prompts persuade users to paste malicious commands into the Windows Run dialog or PowerShell, initiating staged downloads and remote-access payload execution. The operators have also exploited CVE-2026-20131 in Cisco Secure Firewall Management Center for initial access, including exploitation before public disclosure in March 2026.
The ransomware is deployed after broader network compromise. Associated tooling includes NodeSnake, InterlockRAT, Supper, custom JavaScript and Java remote-access trojans, and legitimate remote-administration software. Observed operations involve host and Active Directory reconnaissance, scheduled-task persistence, credential dumping, Kerberoasting, lateral movement, security-software tampering, and data exfiltration before encryption. Operators have abused WinPmem and Volatility3 to obtain password hashes and cached domain credentials from memory, and have used cloud-storage utilities to transfer stolen data. These credential-theft and remote-access functions belong to the wider intrusion toolkit rather than necessarily to the ransomware encryptor itself.
Interlock attacks have caused substantial operational disruption, including interruptions to healthcare services. The operation uses publication of stolen employee, patient, and organizational data as additional leverage alongside the loss of access to encrypted systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The reported May 2025 AMTEC/National Defense Corporation attack included "Exploitation of unpatched CVE-2024-21407 (Windows Kernel privilege escalation flaw)."
Lastly, in a March 2026 report, Amazon threat intelligence documented an Interlock intrusion exploiting CVE-2026-20131, demonstrating the group’s ability to exploit network edge devices to achieve initial access. | Interlock ransomware was also deployed through initial access likely facilitated by SocGholish in January 2025, which led to what appears to be the NodeSnake downloader.
PrintNightmare exploit (Interlock staging)
Local privilege escalation exploit CVE-2023-36036 (JunkFiction-crypted) ... CVE CVE-2023-36036 Local privilege escalation exploit used by Interlock and ModeloRAT operators
Interlock ... concealed ... through the custom Hotta Killer evasion tool, which harnesses a zero-day flaw in the legitimate gaming anti-cheat driver GameDriverx64.sys, tracked as CVE-2025-61155, as part of a Bring Your Own Vulnerable Driver attack. ... kernel termination of security software prior to encryption activities.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Interlock threat actor group uses its own custom ransomware strain, also called "Interlock."
Interlock ransomware is taking a familiar Windows security tool and using it for credential theft.
The Rhysida and Interlock groups, which are known to attack healthcare and other critical infrastructure, have similar TTPs and encryption binaries, leading to some speculation of a connection between the two groups.
The e-crime group is primarily associated with a wide range of malicious tools, including NodeSnake, Interlock RAT, JunkFiction loader, and Interlock ransomware.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The Java variant adds two features... The UpdateThread creates a self-deleting scheduled task... Like the Java variant, the PE uses self-deleting scheduled tasks... A daily scheduled task runs the ransomware at 20:00 as SYSTEM.
A PowerShell-based reconnaissance script systematically collects detailed system and network information, including installed software, running services, browser data, and active connections.
The campaign centers around a flaw affecting Cisco Secure Firewall Management Center (FMC) software... It allows an unauthenticated remote attacker to execute arbitrary Java code with root privileges on affected FMC devices... Interlock had already begun exploiting this flaw as early as January 26, 2026.
The Java variant adds two features... The UpdateThread creates a self-deleting scheduled task... Like the Java variant, the PE uses self-deleting scheduled tasks... A daily scheduled task runs the ransomware at 20:00 as SYSTEM.
The Java variant adds two features... The UpdateThread creates a self-deleting scheduled task... Like the Java variant, the PE uses self-deleting scheduled tasks... A daily scheduled task runs the ransomware at 20:00 as SYSTEM.
A PowerShell-based reconnaissance script systematically collects detailed system and network information... and active connections.
One variant, written in JavaScript... establish[es] encrypted communication with command-and-control servers via WebSockets.
Interlock employs a Bash script that converts compromised Linux servers into HTTP reverse proxies. These proxies forward traffic to attacker-controlled systems while erasing logs every five minutes.
This triggered the next phase of the attack, where Interlock issued commands to download and execute a malicious Linux binary.
Such activity is significant as it often indicates ransomware behavior, where files are encrypted and the originals are deleted.
71 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
65 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group mentioned as having exploited a separate FMC zero-day earlier in 2026.
Interlock is discussed in the context of an ESXi decryptor, indicating ransomware tooling used to decrypt files after payment and revealing details about how the corresponding encryptor works.
A ransomware family/group associated with publishing stolen employee data after payment demands were refused.
Ransomware family/group mentioned as responsible for several attacks against the education sector in the period discussed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.