Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors interlock ransomware group

interlock ransomware group

TLP:CLEAR
Active

Description

In March 2026, 31 high-impact vulnerabilities were identified requiring prioritization for remediation, with 29 receiving Very Critical Risk Scores. Affected vendors included Cisco, Microsoft, Google, ConnectWise, and others, with Microsoft and Apple accounting for approximately 32% of vulnerabilities. Notably, the Interlock Ransomware Group exploited CVE-2026-20131, a zero-day deserialization vulnerability in Cisco Secure Firewall Management Center, as early as January 2026 to compromise enterprise networks. The group deployed custom remote access trojans and facilitated ransomware operations through crafted HTTP requests executing arbitrary Java code as root. Additional campaigns involved the DarkSword iOS exploit kit delivering GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE payloads, and the Coruna exploit kit deploying PlasmaLoader malware. Nine vulnerabilities enabled remote code execution across multiple platforms. One vulnerability dated back nine years, emphasizing continued exploitation of legacy unpatched

AI Analysis

· 2 weeks ago

Executive Summary

The Interlock Ransomware Group emerged in March 2026, exploiting zero-day vulnerabilities and deploying sophisticated ransomware campaigns targeting critical sectors globally. Their primary goal is financial gain through disrupting businesses and extorting ransoms.

Goals & Targeting

The group targets critical infrastructure and enterprise networks across various sectors to achieve financial gains via ransomware extortion. Their victims include high-profile organizations in the US, EU, Japan, and India, focusing on disrupting business continuity.

Enhanced Description

The Interlock Ransomware Group has demonstrated a high level of sophistication by leveraging zero-day vulnerabilities, such as CVE-2026-20131, to compromise enterprise networks. They employ custom remote access trojans and exploit kits like DarkSword and Coruna to deploy payloads such as GHOSTKNIFE, GHOSTSABER, GHOSTBLADE, and PlasmaLoader malware. Targeting sectors including technology, healthcare, and finance, they disrupt businesses through ransomware operations, emphasizing financial gain.

Key Capabilities

  • Custom remote access trojans
  • Exploit kits (DarkSword, Coruna)
  • Zero-day vulnerability exploitation
  • Ransomware deployment via HTTP requests

MITRE ATT&CK Tactics

Defense Evasion
Disruption
Exfiltration
Malware
Initial Access

ATT&CK Techniques

T1059.003
T1021
T1566
T1071
T1394
T1588

Software / Tooling

Custom remote access trojans
DarkSword exploit kit
Coruna exploit kit
GHOSTKNIFE/GHOSTSABER/GHOSTBLADE payloads
PlasmaLoader malware
Mimikatz
Cobalt Strike

Campaigns & Victims

Interlock operates with rapid campaign deployment, targeting multiple sectors and regions. Notable operations include early 2026 attacks using Cisco vulnerabilities and subsequent campaigns leveraging DarkSword and Coruna exploit kits.

IOC Patterns

  • Spear-phishing emails related to patch management
  • Network activity from known C2 domains
  • Unusual RDP session origins
  • Presence of Mimikatz in Event Viewer logs

Recommended Actions

  • Implement proactive patch management and MFA for critical systems
  • Deploy SIEM for threat detection and response
  • Segment sensitive networks to limit lateral movement

Suggested Tags

Ransomware
APT
Financial Motivation
Healthcare Sector
Technology Sector

Confidence Assessment

Medium: Data on TTPs and tools is substantial, but gaps exist in initial compromise vectors beyond zero-days and specific targeting criteria.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Zero-Day Exploitation
Backdoor / C2
APT
Financial Motivation
Healthcare Sector
Technology Sector

Details

Type
Unknown
Confidence
55%
Added
May 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.