logo

Interlock Ransomware Targets Cisco Enterprise Firewalls

ID: 126f4caa-7fbf-5591-a6f1-0fc9647b059b

STIX ID: report--126f4caa-7fbf-5591-a6f1-0fc9647b059b

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-03-20

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Amazon/AWS disclosed that the Interlock ransomware gang exploited a critical zero-day (CVE-2026-20131, CVSS 10) in Cisco Secure Firewall Management Center prior to its March 4 patch, enabling unauthenticated remote arbitrary Java code execution as root; Amazon observed exploitation dating back to Jan. 26 and recovered the actor's toolset from a misconfigured infrastructure server. The advisory describes Interlock's multi-stage campaign—initial exploitation, Windows enumeration scripts, RATs and Java/JavaScript backdoors, disposable relay scripts, memory-resident backdoors, and use of legitimate remote-access tools—and notes that IoCs and detection recommendations were published while urging FMC users to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.