The Interlock ransomware group emerged in and has been spotted worldwide, focusing on North American and European targets in the critical infrastructure, healthcare, and education sectors. They practice double extortion by stealing sensitive data before encrypting systems and threatening to leak information on their "Worldwide Secrets Blog" if demands are not met. The group uses legitimate tools such as Volatility3 for memory analysis and WinPmem for physical memory acquisition.
The Interlock ransomware threat actor has been actively exploiting, a critical-severity zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software. They use ClickFix-style social-engineering methods to lure victims into downloading malicious software. The group also uses a custom-built remote-access trojan called NodeSnake or Interlock RAT for cross-platform persistence and a PHP-based backdoor for persistence on Windows and FreeBSD systems. The exploitation of has a high business impact, affecting critical infrastructure, healthcare, and education sectors.[/subscribe_to_unlock_form]
The Interlock ransomware group emerged in and has been spotted worldwide, focusing on North American and European targets in the critical infrastructure, healthcare, and education sectors. They practice double extortion by stealing sensitive data before encrypting systems and threatening to leak information on their "Worldwide Secrets Blog" if demands are not met. The group uses legitimate tools such as Volatility3 for memory analysis and WinPmem for physical memory acquisition.
The Interlock ransomware threat actor has been actively exploiting, a critical-severity zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software. They use ClickFix-style social-engineering methods to lure victims into downloading malicious software. The group also uses a custom-built remote-access trojan called NodeSnake or Interlock RAT for cross-platform persistence and a PHP-based backdoor for persistence on Windows and FreeBSD systems. The exploitation of has a high business impact, affecting critical infrastructure, healthcare, and education sectors.[emaillocker id="1283"]
The ransomware group's activities have been observed in North America and Europe, with the interval between initial access and lateral movement to the domain controller taking slightly over 26 hours. The attackers took a 24-hour break before redoubling their effort, establishing persistence on the Patient Zero machine and circling back with a fresh plan of attack the next day.
We recommend you to refer this link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1190 | Exploit Public | Facing Application- |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Credential access | T1003.001 | OS Credential Dumping | LSASS Memory |
| Discovery | T1069.002 | Permission Groups Discovery | Domain Groups |
| Lateral Movement | T1021.001 | Remote Services | Remote Desktop Protocol |
| Collection | T1005 | Data from Local System | - |
| Command and Control | T1071 | Application Layer Protocol | - |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Impact | T1486 | Data Encrypted for Impact | - |
The following reports contain further technical details:
[/emaillocker]