Amazon threat intelligence teams identify Interlock ransomware campaign targeting enterprise firewalls
Security Blog
This article details Amazon's discovery of an active Interlock ransomware campaign exploiting CVE-2026-20131, a critical Cisco Secure Firewall Management Center vulnerability, with evidence of zero-day exploitation beginning 36 days before public disclosure.
- Interlock exploited CVE-2026-20131 starting January 26, 2026, before Cisco's March 4 disclosure
- Misconfigured attacker infrastructure exposed complete operational toolkit and attack chain
- Custom remote access trojans built in JavaScript and Java for persistent system control
- Post-compromise reconnaissance script collects OS details, software, network data, and browser artifacts
- Memory-resident webshell uses fileless execution to evade antivirus detection
- Infrastructure laundering script configures proxy servers with aggressive log deletion every five minutes
- Interlock deploys legitimate tools (ScreenConnect, Volatility, Certify) alongside custom malware
- Temporal analysis indicates attackers likely operate in UTC+3 timezone
- Primary targets: education, engineering, construction, manufacturing, healthcare, government sectors
- AWS infrastructure and customer workloads not observed in this campaign
Organizations running Cisco Secure Firewall Management Center should immediately apply security patches, review provided indicators of compromise, and implement defense-in-depth security strategies to protect against Interlock operations.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2025
2025
2025
2025
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.