Interlock ransomware is taking a familiar Windows security tool and using it for credential theft.
The group has turned memory analysis software into a way to pull password hashes and account data from compromised computers.
One compromised workstation became a launch point for a wider breach. ClickFix gave attackers access; they persisted, raised privileges, reached a domain controller, stole data, and locked the victim out of hypervisors.
Sophos analysts identified the activity during a March 2026 response investigation.
The group, tracked as GOLD EMBRACE, has operated since September 2024 and targets organisations in North America and Europe, particularly critical infrastructure, healthcare, and education.
Sophos said in a report shared with Cyber Security News (CSN) that Interlock combines data theft with encryption, then threatens to publish stolen material if demands are not met.
Its multi-stage website delivery campaign relied on compromised sites and fake updates, illustrating how social engineering remains central to its access strategy.
The activity occurred on an unprotected Windows 10 endpoint, the first device compromised.
Interlock used Volatility3, a legitimate tool normally used by responders and researchers to examine a captured memory image, to extract NTLM and legacy LM password hashes plus local account information.
It also ran Volatility3 against cached domain credentials, which can reveal username and hash pairs for people who previously signed in.
The actors collected the memory image with WinPmem, a legitimate acquisition tool. In the victim environment, there was no authorised reason for either tool to be running.
This misuse matters because security teams may expect such utilities during a forensic investigation, not a ransomware intrusion.
A trusted program can hide hostile intent in plain sight, while ClickFix lures also appear in recent trusted-tool attacks aimed at Windows users.
The attack began when a user searching for Dynamics 365 through ChatGPT reached a legitimate website believed to have been compromised.
A ClickFix prompt persuaded the user to paste a command into the Windows Run dialog, downloading PowerShell code and a remote-access payload set to start automatically.
The intruders used a wildcard path to invoke PowerShell, a simple evasion trick intended to reduce detection. Within a little over 26 hours, they had moved from the first device to the domain controller.
On the second day, Interlock queried directory information and performed Kerberoasting, an attack that seeks passwords tied to service accounts.
It then used an anonymous NTLM login in a downgrade attack to move laterally, showing why password theft can place a Windows domain at risk.
By day three, the attackers used a compromised domain administrator account to create a scheduled task on a print server.
Sophos found credential dumping, including cloud credentials, new domain-admin accounts, security-software tampering, access to sensitive files, and data theft before the victim lost hypervisor access.
Interlock has also pursued a critical Cisco firewall management zero-day, a separate route that shows its willingness to combine new flaws with social engineering.
Organisations should treat Cisco firewall zero-day exploitation as another reminder to patch exposed systems quickly and watch for unusual activity after a security alert.
The practical lesson is not to ban every administration or forensic tool. Teams should confirm that endpoint protection is installed and functioning on every server and workstation, define when memory tools are permitted, and alert on unexpected collection or hash-dumping activity.
Organisations should also test backups rather than assuming they can be restored, keep a current asset inventory and network documentation, and review application-control policies regularly.
Monitoring unfamiliar scheduled tasks, suspicious PowerShell activity, and unusual domain queries can help stop an intrusion before encryption begins.
Interlock’s toolset includes NodeSnake, InterlockRAT, and other custom malware.
Reporting on the Interlock and Rhysida connection underlines why defenders should follow behaviour during every stage of an intrusion, not rely solely on a single malware name or file signature.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL | hxxps[://]www[.]redacted[.]com/dynamics-365-business-central-capabilities/?utm_source=chatgpt[.]com | Compromised website URL used in the ClickFix infection chain |
| IP address | 64.95.11.22 | Remote host contacted at the beginning of the intrusion |
| Domain | voginc[.]com | Domain resolving to the initial malicious remote host |
| Domain | afshapiro[.]com | Repository used to retrieve PowerShell code |
| IP address | 104.236.109.139 | Server used to retrieve the remote-access payload |
| File name | zoom.txt | Malicious payload used for process injection |
| Scheduled task | \Microsoft\Windows\Defrag\ScheduledDefrags | Scheduled task created for persistence |
| File name | debug.log | Persistence payload executed through Node.js |
| File name | node.log | Malicious Java payload |
| File name | Win64.exe | Ransomware payload |
| File name | dll.dll | Truncated NtlmThief credential-harvester artifact |
| Domain | browser-updater[.]com | Command-and-control domain |
| URL | hxxp://216.203.20[.]36/debug[.]log | Command-and-control URL |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…