Interlock Weaponizes DFIR Tools to Steal Windows Credentials

The Sophos Emergency Incident Response (EIR) team published a new threat report on August 10, 2026 that details how the ransomware gang Interlock—tracked by Sophos as GOLD EMBRACE—has turned legitimate digital forensics and incident response (DFIR) tools into weapons. By abusing Volatility3, WinPmem, and other commercial utilities, Interlock is able to extract credentials from memory, move laterally across domains, and exfiltrate data before encrypting the victim’s files.

Below is a concise threat overview for security analysts, followed by actionable recommendations to mitigate the risk posed by this evolving adversary.

Attack Narrative

  • Initial Access (T1189 – Drive‑by Compromise): An end‑user visits a compromised web page via a ClickFix lure. The site injects malicious clipboard content, prompting the user to paste a PowerShell command that downloads a RAT payload from an IP controlled by Interlock.
  • Persistence (T1547.001 – Registry Run Keys): The RAT registers a startup entry in the Windows registry and adds a malicious script to the Auto‑Start Extensibility Points.
  • Discovery & Privilege Escalation: The adversary runs LDAP queries (T1069.002) to enumerate domain groups, then exploits Kerberoasting (T1134.003) to harvest service account tickets. Process injection (T1055.002) is used to elevate privileges on the compromised host.
  • Lateral Movement (T1021.001 – Remote Desktop Protocol): With a stolen domain administrator credential, the threat actor connects to a domain controller via RDP and establishes persistence through a scheduled task (T1053.005).
  • Credential Dumping: On the patient‑zero machine, Interlock runs vol.exe -f .\mem.raw windows.hashdump.Hashdump and windows.cachedump.Cachedump to extract NTLM, LM, and cached domain credentials. WinPmem is used to acquire the memory image before analysis.
  • Exfiltration & Extortion: The gang exfiltrates sensitive data and threatens to publish it on its “Worldwide Secrets Blog” if ransom demands are not met.

TTPs Summary

  • Use of legitimate DFIR tools for credential dumping (Volatility3, WinPmem)
  • ClickFix social‑engineering lures
  • Custom RAT (“NodeSnake”/“Interlock RAT”) with PowerShell bootstrapper
  • Exploitation of CVE-2026-20131 in Cisco Secure Firewall Management Center
  • Lateral movement via RDP, Kerberoasting, and scheduled tasks

Detection Indicators

  • Execution of vol.exe with memory file arguments on endpoints not running DFIR tooling
  • Unexpected WinPmem usage or large memory capture files in unusual locations
  • Registry run key creation under HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run
  • New scheduled task named “ScheduledDefrags” or similar suspicious entries
  • Outbound HTTP/HTTPS traffic to domains such as voginc.com, afshapiro.com, or unknown IPs (e.g., 104.236.109.139)

Recommendations for Security Analysts

  • Application Control Policies: Explicitly allow or block DFIR utilities like Volatility and WinPmem on managed endpoints. Enable audit logging for any execution of these tools.
  • Endpoint Detection and Response (EDR): Deploy EDR that monitors credential dumping indicators, PowerShell bootstrap scripts, and registry modifications. Ensure the endpoint is configured to detect Kerberoasting attempts.
  • Patch Management: Apply Cisco patches for CVE-2026‑20131 immediately; maintain a rapid response plan for critical zero‑day vulnerabilities.
  • Network Segmentation & Least Privilege: Restrict RDP access to domain controllers and enforce the principle of least privilege. Use MFA on all administrative accounts.
  • Backup Validation: Regularly test backups and maintain an inventory of virtual environments so that a rebuild can be performed quickly if necessary.
  • Security Awareness Training: Educate users about ClickFix lures, phishing via search engines, and the risks of copying commands from untrusted sources.

Conclusion

The Interlock gang demonstrates that adversaries are increasingly weaponizing legitimate security tools to bypass traditional defenses. By blending DFIR utilities with classic ransomware tactics, they create a multi‑stage attack chain that is difficult to detect without proper visibility and controls. Security analysts should adopt the recommendations above and maintain vigilant monitoring of memory acquisition, credential dumping, and anomalous persistence mechanisms.

“,”excerpt”:”A threat report detailing how Interlock uses legitimate DFIR tools for credential theft, lateral movement, and extortion; includes detection indicators and mitigation strategies.”,”status”:”publish

Leave a Reply

Looking for the Best Cyber Security?

Seamlessly integrate local and cloud resources with our comprehensive cybersecurity services. Protect user traffic at endpoints using advanced security solutions like threat hunting and endpoint protection. Build a scalable network infrastructure with continuous monitoring, incident response, and compliance assessments.

Contact Us

Copyright © 2025 ESSGroup

Discover more from ESSGroup

Subscribe now to keep reading and get access to the full archive.

Continue reading