UnknownUnknown

Interlock Ransomware Group

Ransomware-as-a-service group conducting double extortion attacks across multiple sectors.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
4.5
Moderate signal strength
Mentions6
Sources3
High conf.5
Last seenMay 2026
First observed
Last active
Origin
Aliases
1
Techniques
0
Campaigns
0
TargetsHealthcareTechnologyManufacturing
RegionsGlobal

Attribution signals

6 mentions · 3 sources
#1identifiedhigh
Infrastructure
checkpoint
May 2026

"Researchers identified an Interlock ransomware campaign exploiting CVE-2026-20131, a critical flaw in Cisco Secure Firewall Management Center that enables remote code execution."

#2exploitedhigh
InfrastructureMalware
recorded-future
May 2026

"Interlock Ransomware Group exploited a zero-day in Cisco Secure Firewall Management Center to compromise enterprise networks, deploy custom remote access trojans (RATs), and facilitate ransomware operations."

#3exploitedhigh
Infrastructure
recorded-future
May 2026

"Interlock Ransomware Group exploited CVE-2026-20131 as a zero-day vulnerability beginning January 26, 2026, indicating active exploitation prior to its public disclosure and enabling early compromise of enterprise networks."

#4exploitshigh
TTP matchInfrastructure
recorded-future
May 2026

"The Interlock Ransomware Group exploits vulnerable Cisco FMC instances via crafted HTTP requests exploiting CVE-2026-20131 to execute arbitrary Java code as root."

#5exploitinghigh
TTP match
securelist
May 2026

"The Interlock group has been heavily exploiting the CVE-2026-20131 zero-day vulnerability in Cisco Secure FMC firewall management software since at least January 26, 2026."

#6consistent withmoderate
TTP match
security-affairs
May 2026

"The tools observed were consistent with actors operating in the ransomware ecosystem."

Hedge terms observed

consistent withexploitedexploitingexploitsidentified