← Back to Feed

2608-volatility-interlock

August 4, 2026 · Sophos Threat Research · Severity: MEDIUM

Sophos Threat Research reports that the GOLD EMBRACE threat actor is abusing multiple legitimate Digital Forensics and Incident Response (DFIR) tools in double-extortion attacks. The misuse of tools such as Volatility and Interlock allows attackers to blend in and evade traditional security defenses.

Key Takeaways

  • GOLD EMBRACE group abuses legitimate DFIR tools for double-extortion.
  • Multiple tools like Volatility and Interlock are misused in attacks.
  • Threat actors leverage trusted software to evade detection.
☕ Buy a Coffee