THE Interlock ransomware, identified by Sophos as GOLD EMBRACE, is a double extortion threat targeting critical infrastructure, healthcare, and education sectors in North America and Europe. It utilizes social engineering through a compromised website (ClickFix) for initial access, leveraging the legitimate memory forensics tool Volatility3 to conduct memory-based credential theft. Following initial access, the attackers escalate privileges, move laterally, establish persistence, and exfiltrate data.
They threaten to leak data unless a ransom is paid and employ sophisticated techniques to evade detection, highlighting the risk of legitimate tools being weaponized by cybercriminals. Robust defenses against such tactics are essential, including user training and active endpoint protection.