Interlock ransomware is taking a familiar Windows security tool and using it for credential theft.
The group has turned memory analysis software into a way to pull password hashes and account data from compromised computers.
One compromised workstation became a launch point for a wider breach. ClickFix gave attackers access; they persisted, raised privileges, reached a domain controller, stole data, and locked the victim out of hypervisors.
Sophos analysts identified the activity during a March 2026 response investigation.
The group, tracked as GOLD EMBRACE, has operated since September 2024 and targets organisations in North America and Europe, particularly critical infrastructure, healthcare, and education.
Sophos said in a report shared with Cyber Security News (CSN) that Interlock combines data theft with encryption, then threatens to publish stolen material if demands are not met.
Its multi-stage website delivery campaign relied on compromised sites and fake updates, illustrating how social engineering remains central to its access strategy.
Interlock Turns the Tools Incident Responders Use Into Weapons
The activity occurred on an unprotected Windows 10 endpoint, the first device compromised.
Interlock used Volatility3, a legitimate tool normally used by responders and researchers to examine a captured memory image, to extract NTLM and legacy LM password hashes plus local account information.
It also ran Volatility3 against cached domain credentials, which can reveal username and hash pairs for people who previously signed in.
The actors collected the memory image with WinPmem, a legitimate acquisition tool. In the victim environment, there was no authorised reason for either tool to be running.
This misuse matters because security teams may expect such utilities during a forensic investigation, not a ransomware intrusion.
A trusted program can hide hostile intent in plain sight, while ClickFix lures also appear in recent trusted-tool attacks aimed at Windows users.
The attack began when a user searching for Dynamics 365 through ChatGPT reached a legitimate website believed to have been compromised.
A ClickFix prompt persuaded the user to paste a command into the Windows Run dialog, downloading PowerShell code and a remote-access payload set to start automatically.
The intruders used a wildcard path to invoke PowerShell, a simple evasion trick intended to reduce detection. Within a little over 26 hours, they had moved from the first device to the domain controller.
A fast path to wider disruption
On the second day, Interlock queried directory information and performed Kerberoasting, an attack that seeks passwords tied to service accounts.
It then used an anonymous NTLM login in a downgrade attack to move laterally, showing why password theft can place a Windows domain at risk.
By day three, the attackers used a compromised domain administrator account to create a scheduled task on a print server.
Sophos found credential dumping, including cloud credentials, new domain-admin accounts, security-software tampering, access to sensitive files, and data theft before the victim lost hypervisor access.
Interlock has also pursued a critical Cisco firewall management zero-day, a separate route that shows its willingness to combine new flaws with social engineering.
Organisations should treat Cisco firewall zero-day exploitation as another reminder to patch exposed systems quickly and watch for unusual activity after a security alert.
The practical lesson is not to ban every administration or forensic tool. Teams should confirm that endpoint protection is installed and functioning on every server and workstation, define when memory tools are permitted, and alert on unexpected collection or hash-dumping activity.
Organisations should also test backups rather than assuming they can be restored, keep a current asset inventory and network documentation, and review application-control policies regularly.
Monitoring unfamiliar scheduled tasks, suspicious PowerShell activity, and unusual domain queries can help stop an intrusion before encryption begins.
Interlock’s toolset includes NodeSnake, InterlockRAT, and other custom malware.
Reporting on the Interlock and Rhysida connection underlines why defenders should follow behaviour during every stage of an intrusion, not rely solely on a single malware name or file signature.
Indicators of Compromise (IoCs):-
TypeIndicatorDescriptionURLhxxps[://]www[.]redacted[.]com/dynamics-365-business-central-capabilities/?utm_source=chatgpt[.]comCompromised website URL used in the ClickFix infection chainIP address64.95.11.22Remote host contacted at the beginning of the intrusionDomainvoginc[.]comDomain resolving to the initial malicious remote hostDomainafshapiro[.]comRepository used to retrieve PowerShell codeIP address104.236.109.139Server used to retrieve the remote-access payloadFile namezoom.txtMalicious payload used for process injectionScheduled task\Microsoft\Windows\Defrag\ScheduledDefragsScheduled task created for persistenceFile namedebug.logPersistence payload executed through Node.jsFile namenode.logMalicious Java payloadFile nameWin64.exeRansomware payloadFile namedll.dllTruncated NtlmThief credential-harvester artifactDomainbrowser-updater[.]comCommand-and-control domainURLhxxp://216.203.20[.]36/debug[.]logCommand-and-control URL
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post Interlock Turns the Tools Incident Responders Use Into Weapons for Stealing Windows Passwords appeared first on Cyber Security News.



