← Back to Feed
2608-volatility-interlock
August 4, 2026 · Sophos Threat Research · Severity: MEDIUM
Sophos Threat Research reports that the GOLD EMBRACE threat actor is abusing multiple legitimate Digital Forensics and Incident Response (DFIR) tools in double-extortion attacks. The misuse of tools such as Volatility and Interlock allows attackers to blend in and evade traditional security defenses.
Key Takeaways
- GOLD EMBRACE group abuses legitimate DFIR tools for double-extortion.
- Multiple tools like Volatility and Interlock are misused in attacks.
- Threat actors leverage trusted software to evade detection.