Interlock is a financially motivated ransomware group active since September 2024 and tracked by Sophos as GOLD EMBRACE. The group has targeted organizations in North America and Europe, with repeated victimization in the United States, Canada, and the United Kingdom, and a concentration on critical infrastructure, healthcare, and education. Reported victims also show activity against manufacturing, logistics, and nonprofit organizations. Interlock operates a double-extortion model, stealing data before encrypting systems and threatening public release of stolen material through its leak site if victims do not pay. Publicly reported incidents attribute to the group both data theft and ransomware deployment, including publication of victim data after nonpayment. The group is notable for combining social engineering, hands-on intrusion activity, and opportunistic exploitation of edge infrastructure. Interlock has used ClickFix-style lures delivered via compromised websites and fake update prompts to trick users into executing malicious commands, leading to PowerShell-based payload retrieval and remote-access malware installation. Its tooling has included NodeSnake, also referred to as Interlock RAT, and a PHP-based backdoor used for cross-platform persistence. Reporting also links renewed NodeSnake activity to infrastructure associated with the KongTuke initial access broker. During intrusions, Interlock has demonstrated broad enterprise attack capability: credential theft through abuse of legitimate memory acquisition and forensic tools such as WinPmem and Volatility3; directory discovery; Kerberoasting; anonymous NTLM downgrade-based lateral movement; creation of scheduled-task persistence; creation of new domain administrator accounts; tampering with security tooling; theft of cloud credentials; exfiltration of sensitive files; and ransomware deployment affecting virtualized infrastructure. In one investigated case, the operators moved from an initially compromised endpoint to a domain controller in just over 26 hours and ultimately locked the victim out of hypervisors. Interlock has also been publicly linked to active exploitation of Cisco Secure Firewall Management Center vulnerabilities, including pre-disclosure exploitation of CVE-2026-20131 as a zero-day beginning in late January 2026. This demonstrates capability for initial access via externally exposed enterprise management infrastructure in addition to user-driven social-engineering chains. Available reporting characterizes Interlock as a dedicated ransomware team rather than a confirmed ransomware-as-a-service operator. Known aliases include Interlock and GOLD EMBRACE.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
More recently, Interlock has been actively exploiting CVE-2026-20131, a critical-severity zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software.
Hotta Killer (Interlock): exploits a gaming anti-cheat driver zero-day (CVE-2025-61155) to attack FortiEDR
Local privilege escalation exploit CVE-2023-36036 (JunkFiction-crypted) ... CVE CVE-2023-36036 Local privilege escalation exploit used by Interlock and ModeloRAT operators
89 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware group mentioned as one of the more active groups targeting the education sector during the reporting period.
Conducting ransomware intrusions that combine data theft with encryption and extortion. In this incident, the group used ClickFix social engineering for initial access, abused legitimate forensic tools including Volatility3 and WinPmem for credential theft, moved laterally to a domain controller, stole data, tampered with security tools, and locked the victim out of hypervisors.
Ransomware and double-extortion operations targeting organizations in North America and Europe, using its own malware and conducting its own attacks rather than operating as a RaaS model.
Conducting a ransomware attack and data breach against a healthcare organization, with compromised patient data, client records, medical histories, and internal financial information reportedly exposed.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.