Overview
Platforms:
—
Variants:
—
Extensions:
—
ATT&CK software:
—
Initial access:
Drive-by Compromise · Exploit Public-Facing Application
Top countries:
—
Observed sectors:
—
Tracked victims:
126
Attribution
GOLD EMBRACE
UNCONFIRMED
Vendor tracking name
Hive0163
UNCONFIRMED
Vendor tracking name
Affiliates
No affiliate information available.
Activity
Initial Access
Drive-by compromise
Interlock actors have compromised legitimate websites and used fake browser or software update lures to obtain initial access.
ClickFix social engineering
Victims are presented with fake CAPTCHA or error prompts and instructed to execute malicious commands, commonly through PowerShell.
Exploitation of known vulnerabilities
Amazon Threat Intelligence observed Interlock exploiting CVE-2026-20131 in Cisco Secure Firewall Management Center before public disclosure.
Recent Observations
Activity 5
September 15, 2026
Continued public leak-site activity was observed, indicating that the operation remained active.
Activity 4
June 2026
IBM X-Force documented the wider Interlock malware ecosystem and tracks the operation as Hive0163.
Activity 3
January 26, 2026
Interlock began exploiting CVE-2026-20131 against Cisco Secure Firewall Management Center infrastructure according to Amazon Threat Intelligence.
Activity 2
May 2025
Interlock activity against healthcare and education organizations included custom RATs and evolving ClickFix-based delivery chains.
Activity 1
September 2024
Interlock ransomware first observed, with Windows and cross-platform encryptor development.
TTPs
ATT&CK coverage:
10 techniques
· 8 tactics
T1189
Drive-by Compromise
VERIFIEDInitial Access
Interlock actors compromise legitimate websites and use fake browser or security-software updates to deliver malicious payloads.
T1190
Exploit Public-Facing Application
VERIFIEDInitial Access
Interlock expanded its initial-access tradecraft in 2026 by exploiting CVE-2026-20131 in Cisco Secure Firewall Management Center.
T1204.004
Malicious Copy and Paste
VERIFIEDExecution
Interlock uses ClickFix-style fake CAPTCHA prompts that instruct victims to paste and execute malicious PowerShell commands through the Windows Run dialog.
Show more TTPs (7)
T1059.001
PowerShell
VERIFIEDExecution
Interlock uses PowerShell for payload execution, persistence, tool transfer and reconnaissance.
T1547.001
Registry Run Keys / Startup Folder
VERIFIEDPersistence / Privilege Escalation
Interlock establishes persistence through Windows Startup folders and Registry Run keys, including entries disguised as Chrome updater components.
T1056.001
Keylogging
VERIFIEDCredential Access
Interlock has deployed keylogger components to capture user keystrokes and obtain credentials.
T1021.001
Remote Desktop Protocol
VERIFIEDLateral Movement
Interlock uses compromised credentials with RDP to move between systems in victim environments.
T1219
Remote Access Software
VERIFIEDCommand and Control
Interlock has used legitimate remote-access tools including AnyDesk and other administrative utilities to maintain access and support lateral movement.
T1567.002
Exfiltration to Cloud Storage
VERIFIEDExfiltration
Interlock uses Azure Storage Explorer and AzCopy to stage and exfiltrate stolen data to cloud storage.
T1486
Data Encrypted for Impact
VERIFIEDImpact
Interlock encrypts victim data using AES and RSA-based encryption with payloads supporting Windows, Linux and FreeBSD environments.
Victims
Kettering Health
CONFIRMED
Healthcare organization in United States.
DaVita
CLAIMED
Healthcare organization in United States.
CVEs
Cisco
— Secure Firewall Management Center
Amazon Threat Intelligence identified Interlock ransomware operations exploiting CVE-2026-20131 for unauthenticated remote code execution and subsequent malware deployment.
Associated since:
January 26, 2026
Infrastructure
Infrastructure
Tor-hosted Interlock data leak infrastructure used for victim publication and double-extortion pressure.
Infrastructure
Interlock ransom notes direct victims to a Tor-hosted negotiation portal using unique victim-specific codes rather than including an initial ransom amount.
Infrastructure
Interlock maintains custom malware including NodeSnake, InterlockRAT, JunkFiction downloader and crypter, and related Supper/SocksShell backdoor components.
Infrastructure
During the CVE-2026-20131 campaign, Amazon identified attacker-controlled infrastructure used both to distribute Interlock tooling and to receive operational artifacts from compromised targets.
Timeline
2026-09
Continued active operation
Interlock continued publishing new victim claims in September 2026.
2026-06
Custom malware ecosystem documented
IBM X-Force published long-term research detailing Interlock's custom malware ecosystem and relationships among NodeSnake, InterlockRAT, JunkFiction and related tooling.
2026-03
Zero-day campaign exposed
Amazon publicly documented the Interlock campaign targeting Cisco Secure Firewall Management Center infrastructure.
Show more events (4)
2026-01
Cisco FMC zero-day exploitation begins
Amazon Threat Intelligence later determined that Interlock began exploiting CVE-2026-20131 on January 26, before the vulnerability became public.
2025-07
Joint government advisory
FBI, CISA, HHS and MS-ISAC published a detailed advisory documenting Interlock intrusion techniques, tooling and indicators.
2025-04
DaVita incident
A ransomware incident disrupted DaVita systems. Interlock later claimed responsibility and published data attributed to the organization.
2024-09
Interlock emerges
Interlock ransomware was first observed in late September 2024 targeting organizations in North America and Europe.
Sources
#StopRansomware: Interlock
FBI / CISA / HHS / MS-ISAC
Show more sources (12)
Interlock ransomware group profile
Cyber Threat Intelligence
DaVita Inc. Form 8-K — Cybersecurity Incident
U.S. Securities and Exchange Commission
#StopRansomware: Interlock
FBI / CISA / HHS / MS-ISAC
Ransomware Roundup - Interlock
FortiGuard Labs
Interlock ransomware campaign targeting enterprise firewalls
Amazon Threat Intelligence
Cybersecurity Incident
Kettering Health