Interlock ransomware gang creates volatile situation
2026-08-05T20:51:34Z•ea7af006952b7ed49c8647b2616f5948852c501c28fad223ac8b6a5feab0df66
CVE-2026-18577AI securityDFIR toolsGOLD EMBRACEInterlockMicrosoft Teams vishingN-able N-centralRMMcustom malwaredouble extortionliving-off-the-landnetwork tunnelingpersistenceransomwareremote access toolssocial engineering
What happened
Sophos reporting highlights active ransomware and social-engineering campaigns, including Interlock/GOLD EMBRACE abuse of legitimate DFIR tools, Microsoft Teams vishing involving custom malware and remote access tools, and exploitation of N-able N-central via CVE-2026-18577 to deploy RMM tools and network tunnels for persistent access. The feed also includes AI security and product-development content.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- ea7af006952b7ed49c8647b2616f5948852c501c28fad223ac8b6a5feab0df66
- Enrichment time
- 2026-08-05T20:51:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.