Interlock Ransomware Gang Creates Volatile Situation
Sophos, Tuesday, August 4th, 2026
Sophos investigates Interlock ransomware abusing legitimate DFIR memory-analysis tools including Volatility3.
The Sophos Emergency Incident Response team investigated a March 2026 intrusion by the Interlock ransomware group, tracked by the Sophos Counter Threat Unit as GOLD EMBRACE.
The actors abused legitimate digital forensics tools including Volatility3 and WinPmem during the intrusion.
Entry was gained through ClickFix social engineering, which tricks users into running attacker-supplied commands.
Sophos describes the resulting situation as volatile given the tooling involved.