Threat Advisory

Interlock Ransomware Exploits Cisco Secure Firewall Zero-Day Vulnerability

Threat: Vulnerability
Targeted Region: North America, Europe
Targeted Sector: Technology & IT, Critical Infrastructure, Healthcare
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The Interlock ransomware group emerged in and has been spotted worldwide, focusing on North American and European targets in the critical infrastructure, healthcare, and education sectors. They practice double extortion by stealing sensitive data before encrypting systems and threatening to leak information on their "Worldwide Secrets Blog" if demands are not met. The group uses legitimate tools such as Volatility3 for memory analysis and WinPmem for physical memory acquisition.

The Interlock ransomware threat actor has been actively exploiting, a critical-severity zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software. They use ClickFix-style social-engineering methods to lure victims into downloading malicious software. The group also uses a custom-built remote-access trojan called NodeSnake or Interlock RAT for cross-platform persistence and a PHP-based backdoor for persistence on Windows and FreeBSD systems. The exploitation of has a high business impact, affecting critical infrastructure, healthcare, and education sectors.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The Interlock ransomware group emerged in and has been spotted worldwide, focusing on North American and European targets in the critical infrastructure, healthcare, and education sectors. They practice double extortion by stealing sensitive data before encrypting systems and threatening to leak information on their "Worldwide Secrets Blog" if demands are not met. The group uses legitimate tools such as Volatility3 for memory analysis and WinPmem for physical memory acquisition.

The Interlock ransomware threat actor has been actively exploiting, a critical-severity zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software. They use ClickFix-style social-engineering methods to lure victims into downloading malicious software. The group also uses a custom-built remote-access trojan called NodeSnake or Interlock RAT for cross-platform persistence and a PHP-based backdoor for persistence on Windows and FreeBSD systems. The exploitation of has a high business impact, affecting critical infrastructure, healthcare, and education sectors.[emaillocker id="1283"]

The ransomware group's activities have been observed in North America and Europe, with the interval between initial access and lateral movement to the domain controller taking slightly over 26 hours. The attackers took a 24-hour break before redoubling their effort, establishing persistence on the Patient Zero machine and circling back with a fresh plan of attack the next day.

RECOMMENDATION:

We recommend you to refer this link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1190 Exploit Public Facing Application-
Execution T1059.001 Command and Scripting Interpreter PowerShell
Persistence T1543.003 Create or Modify System Process Windows Service
Credential access T1003.001 OS Credential Dumping LSASS Memory
Discovery T1069.002 Permission Groups Discovery Domain Groups
Lateral Movement T1021.001 Remote Services Remote Desktop Protocol
Collection T1005 Data from Local System -
Command and Control T1071 Application Layer Protocol -
Exfiltration T1041 Exfiltration Over C2 Channel -
Impact T1486 Data Encrypted for Impact -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu