INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Interlock Ransomware Targets Cisco Enterprise Firewalls

| 2026-03-20 13:00 CRITICAL HIGH
Executive Summary AI-generated
The Interlock ransomware gang has been exploiting a critical vulnerability in Cisco's Secure Firewall Management Center (FMC) Software, which can allow an unauthenticated remote attacker to execute arbitrary Java code as root on an impacted device. This is precisely why defense in depth is essential - layered security controls provide protection when any single control fails or hasn't yet been deployed. The gang has been targeting companies with Cisco enterprise firewalls and has used various tactics such as a PowerShell script to enumerate the Windows environment, collect basic data before creating a directory on the attacker's end, and custom remote-access Trojans to gain initial access through exploiting the vulnerability. This rare mistake provided Amazon's security teams with visibility into the ransomware group's multi-stage attack chain, including reconnaissance scripts and evasion techniques. The real story here isn't just about one vulnerability or one ransomware group - it's about the fundamental challenge zero-day exploits pose to every security model.
Technical Mitigations AI-generated
* Implement a patching program that checks for and applies all known vulnerabilities, including the Cisco firewall zero-day (CVE-2026-20131), to minimize the risk of exploitation. * Regularly update software applications and operating systems to ensure they have the latest security patches, even if no patches are available for older versions or critical vulnerabilities like CVE-2026-20131. * Use a vulnerability scanning tool that can detect known zero-day exploits, such as CVE-2026-20131, in real-time and alert administrators to potential threats before an attacker can exploit them. * Conduct regular security audits and penetration testing to identify and address any weaknesses or vulnerabilities in the organization's defenses, including those related to Cisco firewalls and other software applications. * Educate employees on cybersecurity best practices, such as avoiding suspicious links and attachments, using strong passwords, and keeping software up-to-date, to reduce the risk of falling victim to ransomware attacks like Interlock.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20131CVE-2026-20131
Target & Sectors
EUROPE EUROPE NORTH_AMERICA NORTH_AMERICA defensedefense healthhealth governmentgovernment healthcarehealthcare educationeducation
Incident Timeline
September 2024
Threat actors used Interlock ransomware to target Cisco Enterprise Firewalls in North America and Europe.
target_region EUROPE
target_region NORTH_AMERICA
attribution FBI
2025-03-19
The FBI and other federal agencies said the Interlock ransomware gang exploited a vulnerability in Cisco enterprise firewalls to target critical infrastructure and businesses across Europe and North America.
tactic Ransomware
target_region EUROPE
target_region NORTH_AMERICA
attribution FBI
2025-03-20
Threat actors used Recorded Future's H1 2025 Malware and Vulnerability Trends report to identify vulnerabilities in edge security devices, specifically Cisco Enterprise Firewalls.
organisation Recorded Future's
tactic T1588.001 - Malware
organisation Vulnerability Trends
general_metric 2025 H1
general_metric 17 %
January 26
Interlock exploited a vulnerability in Cisco Enterprise Firewalls to launch attacks on January 26.
organisation Moses, Interlock
Jan. 26
Amazon researchers discovered Interlock exploited a previously unknown vulnerability in Cisco Enterprise Firewalls as far back as January 26.
organisation Amazon
vulnerability CVE-2026-20131
organisation Interlock
March 4
Threat actors used the Interlock ransomware gang to target Cisco Enterprise Firewalls due to exploitation of CVE-2026-20131, a critical vulnerability disclosed on March 4.
tactic Ransomware
vulnerability CVE-2026-20131
organisation Amazon Integrated Security
organisation CVE-2026
organisation Cisco Secure Firewall Management Center
March 18
Beast Gang exposes Interlock ransomware server.
tactic Ransomware
organisation Amazon Integrated Security
tactic T1584.004 - Server
2026-03-20
Interlock ransomware gang exploited a zero-day vulnerability in Cisco's Secure Firewall Management Center (FMC) Software.
organisation Amazon
organisation Interlock
infrastructure Windows
organisation Hood Once Interlock
organisation DaVita
organisation Ohio
organisation CVSS
organisation Secure Firewall Management Center
organisation CVE-2026
organisation Cisco Secure FMC
organisation Cisco Security Cloud Control (SCC
organisation Interlock’s
organisation ConnectWise ScreenConnect
organisation Volatility
organisation EU Sanctions Companies
organisation Cisco
organisation Secure Firewall Adaptive Security Appliance
organisation Secure Firewall Threat Defense
organisation Ivanti
organisation SonicWall
organisation Fortinet
organisation FMC
Tactical Metrics
Metrics
infrastructure
​Windows
Affected Product
Metrics
infrastructure
​Ivanti
Affected Product