Interlock used a memory forensics tool to steal the credentials it was built to investigate
2026-08-11Security
A March 2026 Interlock intrusion used Volatility3 — a legitimate incident-response tool — to pull domain credentials, NTLM hashes and account information out of memory. The rest of the chain was a ClickFix lure and PowerShell.