logo

Amazon threat intelligence teams identify Interlock ransomware campaign targeting enterprise firewalls

ID: ce4a4f6e-8c2a-5f0e-b61e-9c7c8515b57a

STIX ID: report--ce4a4f6e-8c2a-5f0e-b61e-9c7c8515b57a

Feed Name: AWS Security Blog

Threat Score
88/100

Date Published: 2026-03-18

Date Updated: 2026-04-27

Author: CJ Moses

...
...

Amazon Threat Intelligence discovered Interlock ransomware exploiting a zero-day vulnerability in Cisco Secure Firewall Management Center (CVE-2026-20131) prior to public disclosure, recovered a misconfigured attacker staging server exposing their full operational toolkit (custom backdoors, reconnaissance scripts, proxy laundering, and negotiation infrastructure), and provided IoCs and mitigation guidance to defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.