The Interlock ransomware gang, also known as GOLD EMBRACE, has escalated its attacks by misusing legitimate digital forensics and incident response (DFIR) tools. This approach enables sophisticated data theft and double-extortion campaigns, heightening risks for organisations across multiple sectors.
Interlock ransomware gang: Abuse of DFIR tools explained
Recent research highlights how the Interlock ransomware gang leverages trusted administrative and DFIR utilities to deepen its intrusions. By exploiting these tools, attackers evade standard security controls and remain undetected for longer periods. The campaign, first detailed by Sophos, reveals a concerning trend of attackers turning defenders’ tools against them.
What happened and when?
In a series of incidents observed in early to mid-2024, Interlock orchestrated targeted attacks using a combination of living-off-the-land techniques and legitimate DFIR software. The gang sought to access sensitive data, exfiltrate information, and maximise extortion leverage. The attacks typically unfolded over several days, with initial access gained through compromised credentials or vulnerable external services.
Once inside, the attackers deployed tools designed for digital forensics and incident response, such as file recovery utilities and memory analysis software. These tools, normally used by security teams to remediate incidents, were instead repurposed to locate, package, and extract valuable data before ransomware deployment.
Who is affected?
The Interlock ransomware gang’s campaign targets organisations of varying sizes, from small enterprises to large corporations. The use of generic, widely-available DFIR tools means that any sector could be at risk, though the group appears to favour targets with valuable intellectual property or sensitive customer data.
- Organisations with weak application control policies
- Firms lacking least privilege enforcement
- Businesses that do not actively monitor for unusual use of administrative tools
Which tools and products are involved?
The attackers have been observed abusing multiple legitimate DFIR utilities. These include tools typically used for file recovery, memory forensics, and system analysis. Although the specific product names are not disclosed in the public report, common examples in the industry include:
- File carving and undelete tools
- Memory dump and analysis utilities
- System and network reconnaissance programs
Importantly, the threat is not tied to a single product or vendor. Instead, the pattern involves using whatever DFIR tools are present or can be introduced into the victim environment, often under the guise of typical administrative activity.
How the Interlock ransomware attack unfolds
Attack chain and double-extortion tactics
The attack typically begins with initial access, often via credential compromise or exploitation of exposed remote services. Once inside, the attackers escalate privileges and move laterally across the network. At this stage, the misuse of DFIR tools becomes central:
- Deployment of DFIR utilities to identify and recover sensitive or previously deleted files
- Exfiltration of data, with attackers using forensic tools to package files for transfer
- Ransomware payload is executed, encrypting the victim’s data and systems
- Victims are threatened with public exposure of stolen data unless the ransom is paid
This double-extortion method, combining both encryption and data theft, increases pressure on victims and complicates recovery efforts.
Timeline and current exploitation status
The misuse of legitimate DFIR tools by the Interlock group was first observed in the first half of 2024. Sophos and other security researchers continue to monitor related activity, reporting that attacks are ongoing and evolving. The use of living-off-the-land techniques means that detection is challenging, as the tools employed often blend in with legitimate administrative activity.
As of June 2024, there is no evidence that a single vulnerability or exploit is responsible for the attacks. Instead, the focus is on abusing existing privileges and trusted tools, making proactive monitoring and behavioural detection critical for defence.
Why these ransomware tactics matter
The Interlock ransomware gang’s tactics underscore a growing trend of attackers repurposing defenders’ own tools for malicious gain. By misusing DFIR utilities, attackers increase the stealth and impact of their campaigns, making traditional detection methods less effective. This approach also complicates incident response and forensic investigations, as the boundary between legitimate and malicious activity becomes blurred.
Immediate actions for organisations
- Monitor for unusual usage of administrative and DFIR tools, including unexpected execution or file access
- Apply strict application control policies to limit which utilities can be run and by whom
- Enforce least privilege principles, ensuring users and admins have only the access they need
- Refine detection rules to identify living-off-the-land behaviours and suspicious use of forensic tools
By addressing these risks, organisations can reduce the likelihood of falling victim to similar double-extortion threats and improve their ability to detect and respond to advanced ransomware campaigns.
Originally reported by sophos.com.






