Interlock Ransomware Targets Cisco Enterprise Firewalls
ID: 126f4caa-7fbf-5591-a6f1-0fc9647b059b
STIX ID: report--126f4caa-7fbf-5591-a6f1-0fc9647b059b
Feed Name: Dark Reading
Amazon/AWS disclosed that the Interlock ransomware gang exploited a critical zero-day (CVE-2026-20131, CVSS 10) in Cisco Secure Firewall Management Center prior to its March 4 patch, enabling unauthenticated remote arbitrary Java code execution as root; Amazon observed exploitation dating back to Jan. 26 and recovered the actor's toolset from a misconfigured infrastructure server. The advisory describes Interlock's multi-stage campaign—initial exploitation, Windows enumeration scripts, RATs and Java/JavaScript backdoors, disposable relay scripts, memory-resident backdoors, and use of legitimate remote-access tools—and notes that IoCs and detection recommendations were published while urging FMC users to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
