Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fake CAPTCHA Installs Malware That Kills 145 Security Processes
August 20, 2026
New Android Malware Steals Banking PINs and Relays Data Through Infected Phones
August 20, 2026
Critical Microsoft 365 Flaw Lets Attackers Bypass MFA, Hijack Mailboxes
August 20, 2026
Home/CyberSecurity News/Cisco ASA, FTD Critical Zero-Day Actively Exploited for Interlock Ransomware
CyberSecurity News

Cisco ASA, FTD Critical Zero-Day Actively Exploited for Interlock Ransomware

Key Takeaways A critical zero-day vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) Software is under active exploitation. The Interlock ransomware group began...

David kimber
David kimber
March 18, 2026 4 Min Read
46 0

Key Takeaways

  • A critical zero-day vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) Software is under active exploitation.
  • The Interlock ransomware group began exploiting the flaw 36 days before Cisco’s public disclosure, gaining a significant head start.
  • The vulnerability allows unauthenticated remote attackers to execute arbitrary Java code with root privileges.
  • Interlock employs a sophisticated toolkit, including custom RATs, legitimate tools, and methods to erase forensic evidence.
  • Organizations are urged to apply the latest security patches immediately and focus on behavioral detection rather than static file hashes.

Cisco Firewall Zero-Day Actively Exploited by Interlock Ransomware

A severe zero-day vulnerability, identified as CVE-2026-20131, within Cisco Secure Firewall Management Center (FMC) Software is currently being leveraged in active attacks by the Interlock ransomware syndicate. This critical flaw allows remote, unauthenticated attackers to execute arbitrary Java code with root privileges on affected systems.

Table Of Content

  • Key Takeaways
  • Cisco Firewall Zero-Day Actively Exploited by Interlock Ransomware
  • Attribution and Targeting Strategy
  • Interlock’s Sophisticated Toolkit and Tactics
  • What You Should Do

Cisco publicly disclosed the vulnerability on March 4, 2026. However, threat intelligence researchers at Amazon uncovered Interlock’s exploitation of this flaw beginning January 26, 2026 — a full 36 days prior to the public announcement. This substantial head start enabled the ransomware group to aggressively compromise organizations before defenders were even aware of the threat. Amazon shared its findings with Cisco to aid in their investigation, confirming that AWS infrastructure and customer workloads were not implicated in this campaign.

The investigation into Interlock’s operations significantly advanced when a misconfigured infrastructure server inadvertently exposed the group’s entire operational toolkit. Early threat activity observed involved HTTP requests directed at a vulnerable software path, containing attempts at Java code execution and embedded URLs. These URLs served to deliver configuration data and confirm successful exploitation by triggering an HTTP PUT request to upload a generated file. By simulating a compromised system, researchers were able to prompt the attackers to deploy a malicious Linux ELF binary. The exposed staging server further revealed that the group meticulously organized artifacts into dedicated paths for each individual target, streamlining both the download of their tools and the upload of exfiltrated operational data.

Attribution and Targeting Strategy

Technical indicators confidently link this ongoing campaign to the Interlock ransomware family, a financially motivated group that first appeared in September 2024. The recovered ELF binary, the embedded ransom note, and the TOR negotiation portal all align with established Interlock branding. Their ransom notes are particularly notable for uniquely citing regulatory exposure, a tactic designed to maximize pressure on victims and consistent with their known double extortion model.

Temporal analysis of timestamps by the Amazon threat intelligence team suggests the actors behind Interlock operate within the UTC+3 timezone. Historically, Interlock focuses its attacks on sectors where operational disruption can force rapid payment, primarily targeting organizations in education, engineering, construction, manufacturing, healthcare, and government.

Interlock’s Sophisticated Toolkit and Tactics

Upon gaining initial access, Interlock deploys a sophisticated array of tools to escalate privileges and maintain persistence within compromised environments. A recovered PowerShell script conducts extensive enumeration of Windows environments, gathering system details, browser artifacts, and network connection information. The script organizes these findings into dedicated directories for each host and compresses them into ZIP archives, indicating preparation for an organization-wide encryption event.

The group employs custom remote access trojans (RATs) implemented in both JavaScript and Java. The JavaScript implant utilizes Windows Management Instrumentation for system profiling and establishes persistent WebSocket connections with RC4-encrypted messages. This provides interactive shell access, file transfer capabilities, and SOCKS5 proxy functionality. A functionally identical Java backdoor, built on GlassFish libraries, ensures redundant access for the attackers.

To obscure their activities, attackers deploy a Bash script that configures Linux servers as HTTP reverse proxies. This script installs HAProxy to forward traffic and aggressively erases logs every five minutes. Additionally, a fileless, memory-resident Java webshell intercepts HTTP requests containing AES-128 encrypted commands using a hardcoded seed.

Interlock also abuses legitimate tools in its operations, including ConnectWise ScreenConnect for remote access, Volatility for memory forensics, and Certify for Active Directory exploitation, alongside its custom malware.

What You Should Do

  • Organizations running Cisco Secure Firewall Management Center must apply the latest security patches immediately to address CVE-2026-20131.
  • Given that the threat actor heavily customized downloaded artifacts for each individual target network, traditional file hashes are largely unreliable for signature-based detection.
  • Defenders should instead prioritize identifying behavioral patterns, memory-resident anomalies, and the specific network reconnaissance tactics associated with Interlock’s multifaceted attack chain.
  • Implement robust network segmentation and multi-factor authentication across all critical systems.
  • Regularly back up critical data and test restoration procedures to minimize the impact of a ransomware attack.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwarePatchransomwareSecurityThreatVulnerabilityzero-day

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Prioritize SOC Tier 1 Triage to Reduce Cybersecurity Costs

Next Post

SnappyClient Malware Combines Remote Access, Data Theft, and Evasion

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Red Hat OpenShift CVE-2023-39418 Exposes Internal Services
August 20, 2026
OpenAI Pauses AI Model Training Over 0-Day Discovery Concerns
August 20, 2026
Cisco AnyConnect VPN Client Critical RCE Vulnerability CVE-2020-3556 Patched
August 20, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us