Most ransomware groups go loud from the beginning. They recruit affiliates publicly, post victim counts on leak sites within weeks of launching, and compete for attention in the cybercriminal ecosystem. Interlock did the opposite. It emerged in late September 2024 operating as a closed group with no public affiliate programme, built its own custom tooling, and spent its first months quietly breaching healthcare networks and universities while the broader threat intelligence community was focused elsewhere.
By July 2025, CISA, the FBI, HHS, and MS-ISAC had issued a joint advisory on the group. By early 2026, Interlock was exploiting a CVSS 10.0 zero-day in Cisco Firepower Management Center — 36 days before Cisco’s public disclosure. Healthcare, education, manufacturing, and, more recently, the US defence industrial base are all in scope.
This is a group that has deliberately and consistently escalated its capabilities. Understanding how it operates matters for every organisation running Cisco network security infrastructure, every NHS trust or US health system with internet-facing clinical systems, and every university that has deployed network security appliances.
How Interlock Is Structured
Interlock does not operate as a ransomware-as-a-service programme in the way that groups like LockBit or RansomHub do. There is no public affiliate recruitment. No forum posts offering access to the ransomware builder. No commission schedule advertised to criminal partners. This is a closed group — internally developed, internally operated, with a consistent technical fingerprint across intrusions.
That structural choice has implications for attribution and for the intelligence picture. Because the same core team is running operations rather than a rotating cast of affiliates, Interlock’s TTPs show more consistency than typical RaaS operations, but also more deliberate capability development. The tools improve between intrusions. The group studies its own operations and adapts.
Arctic Wolf tracks the group under the alias Nefarious Mantis. The core operators appear to work in a UTC+3 timezone based on operational activity patterns.
Initial Access: Three Distinct Methods
Interlock operates with a range of initial access techniques rather than depending on a single vector, which makes perimeter patching alone an insufficient defensive response.
ClickFix social engineering is the most documented initial access method. Victims encounter a compromised website displaying a fake CAPTCHA or “prove you’re human” prompt — typically appearing as a page that claims the browser failed to load content correctly. The victim is instructed to open the Windows Run dialog and paste a command that has been silently placed in the clipboard. The command is a Base64-encoded PowerShell string that, when executed, downloads the first-stage malware. The technique requires no exploit, no unpatched vulnerability — just the victim’s cooperation with a convincing prompt. IBM X-Force and Sekoia documented active ClickFix campaigns linked to Interlock from November 2024 through at least February 2025.
Drive-by downloads using fake browser updates represent a second, parallel initial access path. Users browsing compromised legitimate sites encounter prompts to update Chrome or Edge. The update installer is a malicious executable that begins the infection chain. This technique is operationally distinct from ClickFix — it targets different victim behaviours and requires different defences — but both methods reflect the same core approach: social engineering users into executing malicious content rather than exploiting unpatched browser vulnerabilities.
CVE-2026-20131, the most serious initial access capability Interlock has demonstrated, is a different class of problem entirely. This is an unauthenticated remote code execution vulnerability in Cisco Secure Firepower Management Center (FMC), rated CVSS 10.0. The root cause is insecure Java deserialization (CWE-502). An unauthenticated attacker with network access to the FMC management interface can achieve arbitrary code execution without credentials.
Interlock began exploiting this vulnerability as a zero-day on 26 January 2026. Cisco did not publicly disclose the vulnerability or release a patch until 4 March 2026 — a 36-day window during which organisations running FMC had no vendor-provided mitigation and no CVE to track. Security teams whose defensive posture depended on patch management had no visibility into this risk. The window has since closed for organisations that have patched, but Interlock’s demonstrated willingness to acquire and deploy zero-days significantly raises the threat model for any organisation running Cisco Secure infrastructure.
The Malware Toolkit
Interlock has invested consistently in custom tooling. Its core toolkit comprises two related but distinct remote access tools.
NodeSnake RAT is a first-stage persistent access tool written in Node.js, first identified in January 2025. Its C2 infrastructure uses Cloudflare Tunnel subdomains, which blend with legitimate encrypted web traffic and are difficult to block without disrupting legitimate business operations. NodeSnake provides persistent access, basic lateral movement capabilities, keylogging, and credential harvesting. At universities specifically, it has functioned primarily as a downloader for second-stage tools rather than as a full backdoor.
Interlock RAT is the second-stage backdoor deployed after NodeSnake has established access. Halcyon analysis identified significant code overlaps between NodeSnake and Interlock RAT, suggesting a shared development framework. Interlock RAT provides fuller command-and-control capability including file operations, process execution, and sustained network persistence. A third variant — a PHP-based RAT — was documented from June 2025 onward, indicating active development of the toolkit beyond the initial Node.js framework.
Beyond RATs, infostealers including LummaStealer and BerserkStealer are deployed during the initial access phase to harvest credentials, browser-saved passwords, and session tokens before lateral movement begins. This credential harvest is operationally important: it gives operators authenticated access to cloud services, VPN infrastructure, and internal systems without triggering the same detection signals as brute-force or pass-the-hash attacks.
The group uses both Windows and Linux encryptors, with the Linux variant specifically targeting virtual machine infrastructure. Encrypting hypervisor storage — particularly VMware ESXi — maximises disruption by taking down multiple systems through a single encryption event.
Double Extortion and the Worldwide Secrets Blog
Interlock uses a double extortion model: data is exfiltrated before encryption. In every confirmed intrusion, the group has exfiltrated significant volumes of sensitive data — patient records, student data, financial information, defence supply chain documents — before deploying the encryption payload.
Their dedicated data leak site, which they call the Worldwide Secrets Blog, is accessible via Tor. Victims who do not pay within the negotiation window are publicly named on the leak site with the volume of stolen data, a file count, and a link to the victim’s own website. The ransom note sent to victims does not contain an initial monetary demand — victims receive a unique identifier and are directed to a .onion negotiation portal to open discussions.
The absence of a public ransom figure in the initial note is a deliberate negotiation tactic. It allows Interlock operators to calibrate their demand based on intelligence gathered about the victim organisation’s financial position, insurance coverage, and likely willingness to pay.
Victims and Sector Targeting
Interlock’s targeting across its first eighteen months demonstrates preference for healthcare and education — sectors characterised by high operational sensitivity to downtime, regulatory obligations around personal data, and historically under-resourced security functions.
Texas Tech University Health Sciences Center (TTUHSC) was one of Interlock’s earliest known victims. The breach occurred between 17 and 29 September 2024, within the group’s first weeks of activity. Interlock claimed 2.6 TB of data stolen; TTUHSC’s official notification confirmed 1.46 million individuals were affected. The breach exposed patient records, financial information, and personal identifiers across the health sciences centre’s multiple campuses.
DaVita, a kidney dialysis company with approximately 2,600 outpatient centres and 67,000 employees across the United States, was breached in April 2025. Interlock claimed 1.5 TB of patient and operational data. The attack disrupted dialysis scheduling systems, directly affecting patients dependent on regular treatment.
Kettering Health, a regional health system operating 14 medical centres and 120 outpatient facilities across Ohio, was attacked on 20 May 2025. Interlock claimed 941 GB of stolen data; the breach ultimately resulted in notification to approximately 1.7 million individuals. The system-wide outage affected clinical operations across all facilities simultaneously, forcing diversion of emergency patients and cancellation of elective procedures.
AMTEC Corporation, a subsidiary of National Defense Corporation (NDC) and manufacturer of lethal and non-lethal munitions for the US military, represents Interlock’s expansion into the defence industrial base. NDC’s parent company, National Presto Industries, disclosed a cybersecurity incident in an SEC filing on 6 March 2026. Resecurity’s analysis of the stolen data indicated connections to defence supply chain relationships involving Raytheon, SpaceX, Thales, and Leonardo. Defence contractor data has a different risk profile from healthcare records — the secondary intelligence value to state-linked actors, or actors who might sell to them, is significant.
What Changes With the Cisco FMC Zero-Day
The ClickFix campaigns and drive-by download attacks were serious but not categorically surprising. Social engineering that results in users executing malicious code is a well-documented risk that defenders know how to address. The Cisco FMC zero-day is different in character.
Firepower Management Center is network security infrastructure. It sits inside the perimeter. It is typically managed by the security team rather than end users. Its management interface may not be internet-facing in all deployments, but in many enterprise and healthcare environments it is accessible from a broad internal network segment. An unauthenticated RCE vulnerability in FMC gives an attacker code execution on the device responsible for managing firewall and IPS policy across the network. The impact is not limited to the FMC itself — from that foothold, lateral movement to managed network infrastructure and adjacent systems follows.
The 36-day zero-day window means that organisations patching promptly after vendor disclosure would still have been exposed for over a month. Security teams should audit whether their Cisco FMC installations were internet-accessible or accessible from vulnerable segments during January through March 2026, and should review authentication logs on those systems for any anomalous activity during that period.
Defensive Implications
Patch Cisco FMC immediately if not already patched. CVE-2026-20131 is actively exploited with a CVSS score of 10.0. Any FMC instance not running the March 4, 2026 patch or later should be treated as potentially compromised pending investigation.
Investigate the FMC exposure window. If your FMC was network-accessible from January 26 through March 4, 2026, review authentication logs, outbound connections from the FMC management host, and any anomalous policy changes during that period. The absence of a detected intrusion is not confirmation of no intrusion — Interlock’s post-exploitation dwell time before encryption has extended to weeks in some documented cases.
Deploy ClickFix detections. Sigma and KQL rules for ClickFix technique execution are available from multiple vendors. Key telemetry: PowerShell execution from Run dialog (parent process mmc.exe or explorer.exe), PowerShell command lines containing base64-encoded strings, and clipboard access events preceding script execution.
Restrict FMC management interface access. The management interface for Cisco FMC should not be accessible from general enterprise segments. Restrict access to dedicated management jump hosts with MFA enforced. This does not eliminate the zero-day risk but significantly reduces the attack surface available to remote exploitation.
Alert on Cloudflare Tunnel subdomains in outbound DNS. NodeSnake RAT’s C2 traffic uses Cloudflare Tunnel (trycloudflare.com and related domains). Legitimate business use of Cloudflare Tunnel exists, but alerting on first-seen usage from endpoints that have not previously generated this traffic can surface NodeSnake infections before second-stage deployment.
Review credential hygiene following any social engineering exposure. If a user has executed a ClickFix payload or a fake browser update, treat credentials stored in that browser session — and any systems that user has authenticated to recently — as potentially compromised. LummaStealer and BerserkStealer harvest browser credential stores silently before any visible ransomware activity.
For healthcare organisations specifically: the combination of operational disruption sensitivity, regulatory notification obligations, and patient safety implications makes healthcare systems high-value targets for pressure tactics during negotiation. Interlock has demonstrated consistent willingness to post healthcare data publicly. The deterrence value of robust, air-gapped, frequently tested backups cannot be overstated in this context.