Sophos reported that the Interlock ransomware group, also tracked as GOLD EMBRACE, used legitimate memory-forensics tools including WinPmem and Volatility3 to steal Windows credentials during a March 2026 intrusion. The attack began with a ClickFix social-engineering lure on a compromised website after a user searched for Dynamics 365 via ChatGPT and was tricked into pasting a malicious command. That command downloaded PowerShell code and installed a remote-access payload on an unprotected Windows 10 endpoint, giving the attackers an initial foothold.
Over roughly 26 hours, the attackers conducted LDAP discovery, privilege escalation, Kerberoasting, and NTLM downgrade-based lateral movement before reaching a domain controller. Sophos said Interlock used the forensic tools to extract NTLM and LM hashes, local account data, cached domain credentials, and other secrets, then created new domain-admin accounts, established persistence with a scheduled task and node.exe, tampered with Microsoft Defender, exfiltrated sensitive data including AWS credentials, and ultimately deployed ransomware that locked the victim out of hypervisors. The campaign reflects Interlock’s broader double-extortion operations against organizations in North America and Europe, including critical infrastructure, healthcare, and education, and its use of malware such as NodeSnake and InterlockRAT.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
Sophos Emergency Incident Response investigated the March 2026 ransomware incident and attributed the activity to Interlock, also tracked by the company as GOLD EMBRACE.
During the same March 2026 intrusion, Interlock used WinPmem to capture memory from the initially compromised endpoint and ran Volatility3 to extract NTLM hashes, LM hashes, local account data, and cached domain credentials.
In a March 2026 incident, a user searching for Dynamics 365 through ChatGPT reached a compromised website and was tricked by a ClickFix prompt into pasting a command into the Windows Run dialog. The command downloaded PowerShell code and a RAT payload, establishing persistence on a Windows 10 endpoint.
Sophos said Interlock, which it tracks as GOLD EMBRACE, emerged in September 2024 and has targeted organizations in North America and Europe.
Sophos publicly reported that Interlock had weaponized legitimate forensic tools such as Volatility3 and WinPmem during the March 2026 intrusion, detailing the group's tactics and broader activity.
Later in the intrusion, Sophos found that Interlock dumped additional credentials including cloud credentials, created new domain administrator accounts, tampered with security tools, accessed sensitive files, exfiltrated data, and ultimately deployed ransomware that locked the victim out of hypervisors.
On day three of the intrusion, the attackers used a compromised domain administrator account on a print server to create the scheduled task \Microsoft\Windows\Defrag\ScheduledDefrags, which launched node.exe with debug.log for persistence.
At 01d 02:19:39, Interlock moved from the initial compromised endpoint to a domain controller using anonymous login and an NTLM downgrade attack. Sophos said the attackers reached the domain controller in a little over 26 hours.
At 01d 00:58:22, the attackers queried a service principal name and performed Kerberoasting to obtain credentials associated with service accounts and escalate privileges.
At 01d 00:37:29 into the intrusion, the attackers executed a malicious payload named zoom.txt by leveraging a trusted Microsoft process for code execution.
On the second day of the intrusion, the attackers executed LDAP queries from the compromised endpoint to gather Active Directory information in the victim environment.
Sophos stated that Interlock actively exploited CVE-2026-20131 in Cisco Secure Firewall Management Center Software and that evidence showed the group used it about two weeks before Cisco publicly acknowledged it.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.