securityonline.info 8/10/2026, 8:01:43 AM · external

Interlock Ransomware Abuses Volatility3 for Credential Theft

Interlock Ransomware Abuses Volatility3 for Credential Theft
CyberSIXT Evidence Panel
Primary Source sophos.com
Threat Actor
GOLD EMBRACE

THE Interlock ransomware, identified by Sophos as GOLD EMBRACE, is a double extortion threat targeting critical infrastructure, healthcare, and education sectors in North America and Europe. It utilizes social engineering through a compromised website (ClickFix) for initial access, leveraging the legitimate memory forensics tool Volatility3 to conduct memory-based credential theft. Following initial access, the attackers escalate privileges, move laterally, establish persistence, and exfiltrate data.

They threaten to leak data unless a ransom is paid and employ sophisticated techniques to evade detection, highlighting the risk of legitimate tools being weaponized by cybercriminals. Robust defenses against such tactics are essential, including user training and active endpoint protection.

View Primary Source Via securityonline.info

Article by CyberSIXT