Amazon threat intelligence teams identify Interlock ransomware campaign targeting enterprise firewalls
ID: ce4a4f6e-8c2a-5f0e-b61e-9c7c8515b57a
STIX ID: report--ce4a4f6e-8c2a-5f0e-b61e-9c7c8515b57a
Feed Name: AWS Security Blog
Threat Score
Amazon Threat Intelligence discovered Interlock ransomware exploiting a zero-day vulnerability in Cisco Secure Firewall Management Center (CVE-2026-20131) prior to public disclosure, recovered a misconfigured attacker staging server exposing their full operational toolkit (custom backdoors, reconnaissance scripts, proxy laundering, and negotiation infrastructure), and provided IoCs and mitigation guidance to defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
