Overview

Platforms: —
Variants: —
Extensions: —
ATT&CK software: —
Initial access: Drive-by Compromise · Exploit Public-Facing Application
Top countries: —
Observed sectors: —
Tracked victims: 126

Attribution

GOLD EMBRACE UNCONFIRMED
Vendor tracking name
Hive0163 UNCONFIRMED
Vendor tracking name

Affiliates

No affiliate information available.

Activity

Initial Access

Drive-by compromise
Interlock actors have compromised legitimate websites and used fake browser or software update lures to obtain initial access.
ClickFix social engineering
Victims are presented with fake CAPTCHA or error prompts and instructed to execute malicious commands, commonly through PowerShell.
Exploitation of known vulnerabilities
Amazon Threat Intelligence observed Interlock exploiting CVE-2026-20131 in Cisco Secure Firewall Management Center before public disclosure.

Recent Observations

Activity 5
September 15, 2026
Continued public leak-site activity was observed, indicating that the operation remained active.
Activity 4
June 2026
IBM X-Force documented the wider Interlock malware ecosystem and tracks the operation as Hive0163.
Activity 3
January 26, 2026
Interlock began exploiting CVE-2026-20131 against Cisco Secure Firewall Management Center infrastructure according to Amazon Threat Intelligence.
Activity 2
May 2025
Interlock activity against healthcare and education organizations included custom RATs and evolving ClickFix-based delivery chains.
Activity 1
September 2024
Interlock ransomware first observed, with Windows and cross-platform encryptor development.

TTPs

ATT&CK coverage: 10 techniques · 8 tactics
T1189 Drive-by Compromise
VERIFIED
Initial Access
Interlock actors compromise legitimate websites and use fake browser or security-software updates to deliver malicious payloads.
T1190 Exploit Public-Facing Application
VERIFIED
Initial Access
Interlock expanded its initial-access tradecraft in 2026 by exploiting CVE-2026-20131 in Cisco Secure Firewall Management Center.
T1204.004 Malicious Copy and Paste
VERIFIED
Execution
Interlock uses ClickFix-style fake CAPTCHA prompts that instruct victims to paste and execute malicious PowerShell commands through the Windows Run dialog.
Show more TTPs (7)
T1059.001 PowerShell
VERIFIED
Execution
Interlock uses PowerShell for payload execution, persistence, tool transfer and reconnaissance.
T1547.001 Registry Run Keys / Startup Folder
VERIFIED
Persistence / Privilege Escalation
Interlock establishes persistence through Windows Startup folders and Registry Run keys, including entries disguised as Chrome updater components.
T1056.001 Keylogging
VERIFIED
Credential Access
Interlock has deployed keylogger components to capture user keystrokes and obtain credentials.
T1021.001 Remote Desktop Protocol
VERIFIED
Lateral Movement
Interlock uses compromised credentials with RDP to move between systems in victim environments.
T1219 Remote Access Software
VERIFIED
Command and Control
Interlock has used legitimate remote-access tools including AnyDesk and other administrative utilities to maintain access and support lateral movement.
T1567.002 Exfiltration to Cloud Storage
VERIFIED
Exfiltration
Interlock uses Azure Storage Explorer and AzCopy to stage and exfiltrate stolen data to cloud storage.
T1486 Data Encrypted for Impact
VERIFIED
Impact
Interlock encrypts victim data using AES and RSA-based encryption with payloads supporting Windows, Linux and FreeBSD environments.

Victims

Kettering Health CONFIRMED
May 2025 United States Healthcare
Healthcare organization in United States.
DaVita CLAIMED
April 2025 United States Healthcare 3 tracker sources
Healthcare organization in United States.

CVEs

Cisco — Secure Firewall Management Center
Amazon Threat Intelligence identified Interlock ransomware operations exploiting CVE-2026-20131 for unauthenticated remote code execution and subsequent malware deployment.
Associated since: January 26, 2026

Infrastructure

Infrastructure
Tor-hosted Interlock data leak infrastructure used for victim publication and double-extortion pressure.
Infrastructure
Interlock ransom notes direct victims to a Tor-hosted negotiation portal using unique victim-specific codes rather than including an initial ransom amount.
Infrastructure
Interlock maintains custom malware including NodeSnake, InterlockRAT, JunkFiction downloader and crypter, and related Supper/SocksShell backdoor components.
Infrastructure
During the CVE-2026-20131 campaign, Amazon identified attacker-controlled infrastructure used both to distribute Interlock tooling and to receive operational artifacts from compromised targets.

Timeline

2026-09
Continued active operation
Interlock continued publishing new victim claims in September 2026.
2026-06
Custom malware ecosystem documented
IBM X-Force published long-term research detailing Interlock's custom malware ecosystem and relationships among NodeSnake, InterlockRAT, JunkFiction and related tooling.
2026-03
Zero-day campaign exposed
Amazon publicly documented the Interlock campaign targeting Cisco Secure Firewall Management Center infrastructure.
Show more events (4)
2026-01
Cisco FMC zero-day exploitation begins
Amazon Threat Intelligence later determined that Interlock began exploiting CVE-2026-20131 on January 26, before the vulnerability became public.
2025-07
Joint government advisory
FBI, CISA, HHS and MS-ISAC published a detailed advisory documenting Interlock intrusion techniques, tooling and indicators.
2025-04
DaVita incident
A ransomware incident disrupted DaVita systems. Interlock later claimed responsibility and published data attributed to the organization.
2024-09
Interlock emerges
Interlock ransomware was first observed in late September 2024 targeting organizations in North America and Europe.

Sources