← Back to feed
Breaches & RansomwareEmerging1 sourceAug 10, 2026 · 09:47via CyberPress

Interlock Ransomware Abuses Volatility3 and WinPmem to Dump Windows Credentials From Memory

Brief

Interlock ransomware operators have been observed abusing legitimate forensic tools, Volatility3 and WinPmem, to collect Windows memory and extract credentials from compromised systems.

The activity was identified by Sophos Emergency Incident Response during a March 2026 investigation involving a Windows 10 endpoint.

Sophos tracks Interlock as GOLD EMBRACE, a ransomware group active since September 2024. The group primarily targets organizations in North America and Europe, including critical infrastructure, healthcare, and education entities.

Interlock uses double extortion tactics, stealing sensitive data before encrypting systems and threatening victims with public leaks through its “Worldwide Secrets Blog.”

Unlike many ransomware operations, Interlock does not appear to operate a ransomware-as-a-service model.

Read more on CyberPress