In March 2026, 31 high-impact vulnerabilities were identified requiring prioritization for remediation, with 29 receiving Very Critical Risk Scores. Affected vendors included Cisco, Microsoft, Google, ConnectWise, and others, with Microsoft and Apple accounting for approximately 32% of vulnerabilities. Notably, the Interlock Ransomware Group exploited CVE-2026-20131, a zero-day deserialization vulnerability in Cisco Secure Firewall Management Center, as early as January 2026 to compromise enterprise networks. The group deployed custom remote access trojans and facilitated ransomware operations through crafted HTTP requests executing arbitrary Java code as root. Additional campaigns involved the DarkSword iOS exploit kit delivering GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE payloads, and the Coruna exploit kit deploying PlasmaLoader malware. Nine vulnerabilities enabled remote code execution across multiple platforms. One vulnerability dated back nine years, emphasizing continued exploitation of legacy unpatched
Executive Summary
The Interlock Ransomware Group emerged in March 2026, exploiting zero-day vulnerabilities and deploying sophisticated ransomware campaigns targeting critical sectors globally. Their primary goal is financial gain through disrupting businesses and extorting ransoms.
Goals & Targeting
The group targets critical infrastructure and enterprise networks across various sectors to achieve financial gains via ransomware extortion. Their victims include high-profile organizations in the US, EU, Japan, and India, focusing on disrupting business continuity.
Enhanced Description
The Interlock Ransomware Group has demonstrated a high level of sophistication by leveraging zero-day vulnerabilities, such as CVE-2026-20131, to compromise enterprise networks. They employ custom remote access trojans and exploit kits like DarkSword and Coruna to deploy payloads such as GHOSTKNIFE, GHOSTSABER, GHOSTBLADE, and PlasmaLoader malware. Targeting sectors including technology, healthcare, and finance, they disrupt businesses through ransomware operations, emphasizing financial gain.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Interlock operates with rapid campaign deployment, targeting multiple sectors and regions. Notable operations include early 2026 attacks using Cisco vulnerabilities and subsequent campaigns leveraging DarkSword and Coruna exploit kits.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Medium: Data on TTPs and tools is substantial, but gaps exist in initial compromise vectors beyond zero-days and specific targeting criteria.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics