HomeSecurityInterlock Ransomware: Cisco FMC Zero-Day Exploit

Interlock Ransomware: Exploitation of Cisco FMC Zero-Day

Amazon Threat Intelligence is warning of an active Interlock ransomware campaign that exploits a recently disclosed critical security vulnerability in Cisco Secure Firewall Management Center (FMC) Software. The vulnerability, known as CVE-2026-20131, has a CVSS score of 10.0 and concerns the insecure deserialization of a user-supplied Java byte stream. This could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary Java code as root on an affected device.

See also: LeakNet Ransomware group uses ClickFix techniques

Interlock ransomware
Interlock Ransomware: Exploitation of Cisco FMC Zero-Day

According to data collected from the tech giant's global MadPot , this vulnerability has reportedly been exploited as a zero-day since January 26, 2026, more than a month before it was publicly disclosed by Cisco.

“This wasn’t just another vulnerability exploit. The Interlock ransomware had a zero-day on its hands, giving it a week-long head start to compromise organizations before defenders even knew what to look for. Following this discovery, we shared our findings with Cisco to support their investigation and protect customers,” said CJ Moses, chief information security officer (CISO) for Amazon Integrated Security, in a report.

The discovery was made possible by an operational security error on the part of the attacker, which exposed the cybercrime group’s operational toolkit via a misconfigured infrastructure server, providing insight into the multi-layered attack chain, custom remote access trojans, detection scripts, and evasion techniques. The attack chain involves sending custom HTTP requests to a specific path to the affected software with the goal of executing arbitrary Java code, after which the compromised system issues an HTTP PUT to an external server to confirm successful exploitation.

Once this step is complete, commands are sent to retrieve an ELF binary from a remote server, which hosts other tools associated with the Interlock ransomware. A PowerShell reconnaissance script is used to systematically record the Windows environment, collecting details about the operating system and hardware, running services, installed software, storage configuration, Hyper-V virtual machine registry, user file lists in the Desktop, Documents , and Downloads, browsing logs from Chrome, Edge, Firefox, Internet Explorer , and 360 browsers, active network connections, and RDP authentication events from the Windows event logs.

See also: Hive0163 uses AI malware Slopoly in ransomware attacks

Interlock Ransomware: Exploitation of Cisco FMC Zero-Day
Interlock Ransomware: Exploitation of Cisco FMC Zero-Day

Custom remote access trojans written in JavaScript and Java provide command and control capabilities, interactive shell access, arbitrary command execution, bidirectional file transfer, and SOCKS5 proxy. They also support self-update and self-delete mechanisms to replace or remove the artifact without having to re-enter the machine and causing difficulties in forensic investigation.

A Bash script is used to configure Linux servers as HTTP reverse proxies to hide the attacker's true origins. The script delivers fail2ban, an open source intrusion prevention tool for Linux, and composes and starts an HAProxy that listens on port 80 and forwards all incoming HTTP traffic to a hardcoded target IP address.

Additionally, the infrastructure cleanup script runs a log file deletion routine as a cron job every five minutes to aggressively delete and purge the contents of *.log and suppress shell history by disabling the HISTFILE. A web shell that remains in memory inspects incoming requests for specially crafted parameters containing encrypted command payloads, which are then decrypted and executed.

A lightweight network beacon is used to communicate with infrastructure controlled by the attacker, likely to validate successful code execution or confirm the accessibility of network ports after the initial exploitation.

See also: The Evolution of Ransomware in 2026: Techniques and Organizational Protection

Interlock Ransomware: Exploitation of Cisco FMC Zero-Day
Interlock Ransomware: Exploitation of Cisco FMC Zero-Day

ConnectWise ScreenConnect is used for persistent remote access and acts as a fallback path in case other bases are discovered and removed. The Volatility Framework, an open source memory forensics framework, is also tied into the feature.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS