https://securityaffairs.com/189636/malware/interlock-group-exploiting-the-cisco-fmc-flaw-cve-2026-20131-36-days-before-disclosure.html
#securityaffairs #hacking #malware
The Flow: A fake "Verify You Are Human" prompt leads to Node.js C2 (interlock RAT), followed by hands-on-keyboard activity where they use vol.exe from \AppData\Local\Temp\ to harvest credentials.
Defender Tip: Monitor for vol.exe or python.exe interacting with memory dump files in user temp folders. If you see Hashdump in your logs and it isn't your IR team... you have a live intrusion.
Want more info? Get in touch!
#CyberSecurity #Ransomware #BlueTeam #DFIR #Interlock #Infosec
[INTERLOCK] - Ransomware Victim: Delta Manufacturing - https://www.redpacketsecurity.com/interlock-ransomware-victim-delta-manufacturing/
#interlock #dark_web #data_breach #OSINT #ransomware #threatintel #tor
#AI-generated #Slopoly #malware used in #Interlock #ransomware attack
[INTERLOCK] - Ransomware Victim: Elliott-Lewis - https://www.redpacketsecurity.com/interlock-ransomware-victim-elliott-lewis/
#interlock #dark_web #data_breach #OSINT #ransomware #threatintel #tor
[INTERLOCK] - Ransomware Victim: Wagon Mound Public Schools - https://www.redpacketsecurity.com/interlock-ransomware-victim-wagon-mound-public-schools/
#interlock #dark_web #data_breach #OSINT #ransomware #threatintel #tor