Interlock ransomware uses Cisco FMC flaw CVE-2026-20131 to gain root access.
Mar 18, 2026 // 21:36 - Niko Dunn


Amazon Threat Intelligence is alerting users to an ongoing Interlock ransomware attack that’s exploiting a newly discovered critical vulnerability in Cisco Secure Firewall Management Center (FMC) Software.

The vulnerability, identified as CVE-2026-20131 (with a CVSS score of 10.0), involves the insecure deserialization of a Java byte stream provided by the user. This allows a remote, unauthenticated attacker to bypass authentication and execute arbitrary Java code as root on a vulnerable device.

Data from the tech giant’s MadPot global sensor network suggests the vulnerability was exploited as a zero-day from January 26, 2026, over a month before Cisco’s public announcement.

“This was more than just a regular vulnerability exploitation; Interlock had a zero-day exploit, giving them a week’s advantage in compromising organizations before defenses were even aware. Upon discovery, we reported the findings to Cisco, aiding their investigation and the protection of their customers,” stated CJ Moses, CISO of Amazon Integrated Security, in a report shared with The Hacker News.

Amazon explained that the discovery was facilitated by a mistake made by the attacker, which exposed their cybercrime group’s tools via a misconfigured infrastructure server. This exposure revealed their multi-stage attack process, custom remote access trojans, reconnaissance scripts, and circumvention strategies.

The attack sequence involves sending crafted HTTP requests to a specific path within the vulnerable software to execute arbitrary Java code. The compromised system then sends an HTTP PUT request to an external server to confirm successful exploitation. Upon confirmation, commands are issued to retrieve an ELF binary from a remote server hosting other Interlock-related tools.

The identified tools include:

  • A PowerShell reconnaissance script used to systematically gather information about Windows environments, including the OS and hardware, running services, installed software, storage configurations, a list of Hyper-V virtual machines, user files from Desktop, Documents, and Downloads, browser data from Chrome, Edge, Firefox, Internet Explorer, and 360 browser, network connections, and RDP authentication events from Windows logs.
  • Custom-built remote access trojans, programmed in JavaScript and Java, providing command-and-control capabilities, interactive shell access, arbitrary command execution, two-way file transfer, and SOCKS5 proxy functionality. These trojans also support self-updates and deletions, allowing them to be replaced or removed without re-infecting the system, making forensic investigation more difficult.
  • A Bash script that configures Linux servers as HTTP reverse proxies to hide the attacker’s origin. This script installs fail2ban, an open-source intrusion prevention tool, and sets up an HAProxy instance listening on port 80 that forwards all inbound HTTP traffic to a pre-defined target IP address. Furthermore, that script routinely clears important system logs, as well removes shell artifacts that could lead to discovery.
  • A web shell that resides in memory. It is designed to inspect incoming requests for specially crafted parameters containing encrypted commands. The commands are decrypted and executed.
  • A lightweight network beacon deployed to validate code execution of a specific vulnerability or testing inbound network port reachability.
  • ConnectWise ScreenConnect providing persistent access as an alternate access pathway should other initial attack vectors be detected and removed.
  • Volatility Framework, an open-source memory forensics toolkit

The connection to Interlock is based on related technical and operational indicators, including the ransom note and TOR negotiation portal. Evidence suggests that the threat actor likely operates within the UTC+3 time zone.

Given the active exploitation of this vulnerability, it’s recommended that users promptly apply patches, perform security checks for potential compromises, audit ScreenConnect deployments for unauthorized installations, and enforce defense-in-depth security measures.

“This is not only an exploit campaign by a single ransomware group but the fundamental challenge that zero-day vulnerabilities pose to entire security models,” says Moses. “Even the most up-to-date patching cadence is unable to protect against as yet unknown exploits.”

“Defense in depth is therefore extremely important, and security controls that are layered provide protection when single controls fail. Rapid patching is essential in vulnerability management to avoid the critical exploitation window.

This announcement comes as Google revealed that ransomware groups are adapting their strategies due to decreased payment success, by targeting vulnerabilities in common VPNs and firewalls for initial access. Also, actors are relying more on native Windows capabilities and less on external tools.

Malvertising and SEO tactics have been observed as mechanisms for distributing malware payloads for initial access. Other techniques include using compromised credentials, creating backdoors, deploying remote access software, and using native tools for reconnaissance.

“Although we expect ransomware to stay a primary threat globally, reduced profitability may compel some actors to explore other means of generating revenue,” Google stated. “Such methods could include increased data theft extortion attempts, the employment of more aggressive extortion tactics, or, opportunistically, the use of access to victim environments for secondary monetization mechanisms such as using compromised infrastructure to send phishing messages.”

#(fmc)  #access  #cisco  #cve-2026-20131  #flaw  #gain  #interlock  #news  #ransomware  #root  #uses   —   News