Interlock group exploiting the CISCO FMC flaw CVE-2026-20131 36 days before disclosure
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头,直接写描述。首先,我需要仔细阅读这篇文章,理解它的主要内容。 文章主要讲的是Interlock勒索软件集团利用Cisco FMC的一个零日漏洞CVE-2026-20131进行攻击。这个漏洞是在2026年1月底被利用的,而公开披露是在3月初。也就是说,攻击者在漏洞公开前36天就开始利用它了。 文章还提到,这个漏洞是一个远程代码执行漏洞,存在于Cisco FMC的Web界面中,允许未经身份验证的远程攻击者通过发送恶意序列化对象来执行任意代码。这使得攻击者能够以root权限控制设备。 此外,Interlock集团自2024年9月以来一直活跃,并且最近使用了一种新的AI辅助恶意软件Slopoly。亚马逊的研究人员通过honeypot发现了这次攻击,并与Cisco合作进行调查。 最后,文章指出Interlock集团的工具包被暴露出来,揭示了他们的多阶段攻击、定制后门、侦察工具和规避方法。研究人员还提供了检测指标和防御建议。 现在我需要将这些信息浓缩到100字以内。重点包括:Interlock集团利用CVE-2026-20131零日漏洞攻击Cisco FMC,在漏洞披露前36天开始;该漏洞允许远程代码执行;亚马逊通过honeypot发现并协助调查;以及该集团的多阶段攻击和工具包暴露。 确保语言简洁明了,直接描述内容,不使用任何开头语。 </think> Interlock 勒索软件团伙利用 Cisco FMC 零日漏洞 CVE-2026-20131 进行攻击,在漏洞披露前 36 天开始行动。该漏洞允许未经身份验证的远程攻击者通过 Java 反序列化执行任意代码。研究人员通过蜜罐发现此活动,并与 Cisco 合作调查。 2026-3-19 09:22:32 Author: securityaffairs.com(查看原文) 阅读量:6 收藏

Interlock group exploiting the CISCO FMC flaw CVE-2026-20131 36 days before disclosure

The Interlock ransomware group has exploited a Cisco FMC zero-day RCE vulnerability in attacks since late January.

The Interlock ransomware group has been exploiting a critical zero-day RCE vulnerability, tracked as CVE-2026-20131 (CVSS score of 10.0), in Cisco Secure Firewall Management Center (FMC) since late January.

The vulnerability is a remote code execution flaw that resides in Cisco Secure FMC’s web interface and allows unauthenticated remote attackers to exploit insecure Java deserialization and execute arbitrary code as root by sending a crafted serialized object.

“A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.” reads the advisory. “This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root.”

CVE-2026-20131 also impacts Cisco Security Cloud Control (SCC) Firewall Management. The networking giant addressed the flaw in early March 2026.

Interlock ransomware group has been active since September 2024, it has targeted multiple organizations, including DaVita, Kettering Health, and Texas Tech University. Recently, researchers observed a new AI-assisted malware strain called Slopoly used in its operations.

Amazon researchers observed the Interlock group exploiting the CVE-2026-20131 flaw 36 days before disclosure, starting on January 26, 2026. This gave attackers time to compromise targets before detection. The activity was uncovered via honeypots and shared with Cisco to aid in the investigation and protect customers.

“After Cisco’s disclosure, Amazon threat intelligence began research into this vulnerability using Amazon MadPot’s global sensor network—a system of honeypot servers that attract and monitor cybercriminal activity. While looking for any current or past exploits of this vulnerability, our research found that Interlock was exploiting this vulnerability 36 days before its public disclosure, beginning January 26, 2026.” reads the report published by Amazon. “This wasn’t just another vulnerability exploit, Interlock had a zero-day in their hands, giving them a week’s head start to compromise organizations before defenders even knew to look. Upon making this discovery, we shared our findings with Cisco to help support their investigation and protect customers.”

A misconfigured server exposed Interlock’s full toolkit, revealing its multi-stage attacks, custom backdoors, reconnaissance tools, and evasion methods. AWS pointed out that its systems were not affected. The findings provide detailed indicators to help detect compromises, and organizations using Cisco FMC are urged to apply patches and review the shared indicators immediately.

“Amazon threat intelligence identified threat activity potentially related to CVE-2026-20131 beginning January 26, 2026, predating the public disclosure.” continues the report. “Observed activity involved HTTP requests to a specific path in the affected software. Request bodies contained Java code execution attempts and two embedded URLs: one used to deliver configuration data supporting the exploit, and another designed to confirm successful exploitation by causing a vulnerable target to perform an HTTP PUT request and upload a generated file. Multiple variations of these URLs were observed across different exploit attempts.”

Researchers mimicked a compromised system to trigger Interlock’s next step, leading to the download of a malicious Linux binary. Analysis showed a single server hosted the group’s full toolkit, organizing files by target and using the same paths to both deploy tools and collect stolen data.

The recovered ELF malware is attributed to the Interlock ransomware group based on consistent ransom notes, TOR negotiation portals, and unique victim IDs used for tracking. The group is known for targeting sectors where disruption drives payment, including education, healthcare, industry, and government. Timeline analysis suggests operators likely work in a UTC+3 timezone.

After initial access, Interlock deploys PowerShell scripts to systematically map compromised networks, collecting system, user, and browser data across multiple machines. They then use custom remote access trojans (in JavaScript and Java) to maintain persistent control, execute commands, transfer files, and exfiltrate data via encrypted communications.

To hide their activity, attackers set up proxy-based relay infrastructure that masks the origin of attacks and regularly wipes logs to erase evidence. They also use fileless webshells that run entirely in memory, decrypting and executing malicious code without touching disk—making detection by traditional security tools far more difficult.

Researchers found a simple Java tool acting as a “phone home” beacon, confirming access by logging connections on a hidden port. Interlock also abused legitimate tools like ConnectWise ScreenConnect for stealthy remote access, ensuring persistence if malware is removed. Additional tools such as Volatility and Certify were used to extract credentials, move laterally, escalate privileges, and maintain long-term control of compromised systems.

Amazon provided Indicators of compromise (IoCs) for these attacks and defensive recommendations.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CVE-2026-20131)




文章来源: https://securityaffairs.com/189636/malware/interlock-group-exploiting-the-cisco-fmc-flaw-cve-2026-20131-36-days-before-disclosure.html
如有侵权请联系:admin#unsafe.sh