Interlock, tracked by Sophos as GOLD EMBRACE, is a financially motivated ransomware group active since September 2024. It targets organizations in North America and Europe, with observed emphasis on critical infrastructure, healthcare, education, and public-sector entities. The group conducts double-extortion operations, stealing data before encrypting victim systems and threatening publication through its leak site. Interlock has claimed attacks against U.S. healthcare providers, manufacturers, and local-government organizations. Interlock has used ClickFix and fake-CAPTCHA social-engineering lures delivered through compromised websites to induce victims to execute malicious commands. Observed intrusions involved PowerShell-based payload delivery, custom remote-access tooling including NodeSnake (Interlock RAT), use of Node.js for persistence, scheduled tasks, directory-service discovery, credential dumping, Kerberoasting, NTLM downgrade attacks, creation of domain-administrator accounts, lateral movement to domain controllers, security-tool tampering, data theft, and ransomware deployment affecting virtualized infrastructure. The group has also abused legitimate memory-acquisition and forensic tools to extract local, domain, and cached credentials from memory. Interlock has deployed ransomware affecting ESXi environments and was identified exploiting CVE-2026-20131, a critical Cisco Secure Firewall Management Center remote-code-execution vulnerability, as a zero-day beginning in January 2026. Sophos assesses Interlock as a small dedicated team rather than a ransomware-as-a-service operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Amazon reported that the Interlock ransomware group has been exploiting the maximum severity vulnerability, CVE-2026-20131 (CVSS: 10), in Cisco Secure Firewall Management Center (FMC) software, since January 2026. Disclosed on March 4th, CVE-2026-20131 is a Remote Code Execution vulnerability impacting Cisco Secure Firewall Management Center (FMC) software.
Hotta Killer (Interlock): exploits a gaming anti-cheat driver zero-day (CVE-2025-61155) to attack FortiEDR
Local privilege escalation exploit CVE-2023-36036 (JunkFiction-crypted) ... CVE CVE-2023-36036 Local privilege escalation exploit used by Interlock and ModeloRAT operators
104 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as one of several ransomware families tied to Woodgnat/KongTuke.
Conducted a ransomware/data-extortion attack against Super Systems Inc and claimed to possess confidential customer control schemes, customer-system vulnerabilities, client portfolio and account data, customer contact and pricing lists, intellectual property, and process-control software.
Claimed responsibility for a separate April 2026 ransomware attack against Winona County, Minnesota, and leaked a substantial amount of data from that breach.
Conducting a ransomware attack against Connell Enterprises LLC.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.