Interlock Turns the Tools Incident Responders Use Into Weapons for Stealing Windows Passwords
A criminal group is using a trusted Windows troubleshooting tool in a harmful way to steal saved sign-in data from infected computers. In the reported case, one infected work computer helped the attackers spread further inside the organization.
Who is at risk
People and organizations using Windows computers are most at risk, especially if a work device has been exposed to fake software prompts, suspicious downloads, or unexpected remote access requests.
What to watch for
Watch for unexpected pop-ups asking you to run fixes, strange login prompts, disabled security settings, unusually slow computers, or account lockouts and sign-in alerts you did not expect.
What to do
If you suspect a Windows computer was tricked into running an unknown fix or tool, disconnect it from the internet immediately, change important passwords from a different device, and contact your IT provider or security support right away.
