Interlock Ransomware Gang Misuses DFIR Tools

Interlock ransomware abusing legitimate DFIR tools for double extortion

The Interlock ransomware gang, also known as GOLD EMBRACE, has escalated its attacks by misusing legitimate digital forensics and incident response (DFIR) tools. This approach enables sophisticated data theft and double-extortion campaigns, heightening risks for organisations across multiple sectors.

Interlock ransomware gang: Abuse of DFIR tools explained

Recent research highlights how the Interlock ransomware gang leverages trusted administrative and DFIR utilities to deepen its intrusions. By exploiting these tools, attackers evade standard security controls and remain undetected for longer periods. The campaign, first detailed by Sophos, reveals a concerning trend of attackers turning defenders’ tools against them.

What happened and when?

In a series of incidents observed in early to mid-2024, Interlock orchestrated targeted attacks using a combination of living-off-the-land techniques and legitimate DFIR software. The gang sought to access sensitive data, exfiltrate information, and maximise extortion leverage. The attacks typically unfolded over several days, with initial access gained through compromised credentials or vulnerable external services.

Once inside, the attackers deployed tools designed for digital forensics and incident response, such as file recovery utilities and memory analysis software. These tools, normally used by security teams to remediate incidents, were instead repurposed to locate, package, and extract valuable data before ransomware deployment.

Who is affected?

The Interlock ransomware gang’s campaign targets organisations of varying sizes, from small enterprises to large corporations. The use of generic, widely-available DFIR tools means that any sector could be at risk, though the group appears to favour targets with valuable intellectual property or sensitive customer data.

  • Organisations with weak application control policies
  • Firms lacking least privilege enforcement
  • Businesses that do not actively monitor for unusual use of administrative tools

Which tools and products are involved?

The attackers have been observed abusing multiple legitimate DFIR utilities. These include tools typically used for file recovery, memory forensics, and system analysis. Although the specific product names are not disclosed in the public report, common examples in the industry include:

  • File carving and undelete tools
  • Memory dump and analysis utilities
  • System and network reconnaissance programs

Importantly, the threat is not tied to a single product or vendor. Instead, the pattern involves using whatever DFIR tools are present or can be introduced into the victim environment, often under the guise of typical administrative activity.

How the Interlock ransomware attack unfolds

Attack chain and double-extortion tactics

The attack typically begins with initial access, often via credential compromise or exploitation of exposed remote services. Once inside, the attackers escalate privileges and move laterally across the network. At this stage, the misuse of DFIR tools becomes central:

  1. Deployment of DFIR utilities to identify and recover sensitive or previously deleted files
  2. Exfiltration of data, with attackers using forensic tools to package files for transfer
  3. Ransomware payload is executed, encrypting the victim’s data and systems
  4. Victims are threatened with public exposure of stolen data unless the ransom is paid

This double-extortion method, combining both encryption and data theft, increases pressure on victims and complicates recovery efforts.

Timeline and current exploitation status

The misuse of legitimate DFIR tools by the Interlock group was first observed in the first half of 2024. Sophos and other security researchers continue to monitor related activity, reporting that attacks are ongoing and evolving. The use of living-off-the-land techniques means that detection is challenging, as the tools employed often blend in with legitimate administrative activity.

As of June 2024, there is no evidence that a single vulnerability or exploit is responsible for the attacks. Instead, the focus is on abusing existing privileges and trusted tools, making proactive monitoring and behavioural detection critical for defence.

Why these ransomware tactics matter

The Interlock ransomware gang’s tactics underscore a growing trend of attackers repurposing defenders’ own tools for malicious gain. By misusing DFIR utilities, attackers increase the stealth and impact of their campaigns, making traditional detection methods less effective. This approach also complicates incident response and forensic investigations, as the boundary between legitimate and malicious activity becomes blurred.

Immediate actions for organisations

  • Monitor for unusual usage of administrative and DFIR tools, including unexpected execution or file access
  • Apply strict application control policies to limit which utilities can be run and by whom
  • Enforce least privilege principles, ensuring users and admins have only the access they need
  • Refine detection rules to identify living-off-the-land behaviours and suspicious use of forensic tools

By addressing these risks, organisations can reduce the likelihood of falling victim to similar double-extortion threats and improve their ability to detect and respond to advanced ransomware campaigns.

Originally reported by sophos.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call