Quick Summary
AllegedExecutive Summary
AngMar Companies was identified as a victim by the Interlock ransomware group on August 11, 2026. SOCRadar’s Dark Web Monitoring service flagged a significant credential exposure associated with the angmarcompanies[.]com domain, specifically involving a single high-privilege account. This exposure is particularly concerning as it impacts critical infrastructure, including identity provider and email security gateways, potentially facilitating corporate intrusion. Interlock has maintained a selective targeting strategy, claiming only six other victims in the preceding 60 days. Their recent activity primarily targets the manufacturing sector, with some involvement in healthcare and public sector organizations across the United States, Canada, and the United Kingdom. Previous victims listed by Interlock include Gardiner Family Chiropractic, Centre for Newcomers, Paragon Store Fixtures, and Converting Equipment International. While AngMar Companies’ specific industry and country could not be definitively resolved from the provided information, the group’s focus on North American and Anglophone regions suggests a potential overlap.
Technical Analysis
SOCRadar’s stealer-log telemetry identified ten records linked to the angmarcompanies[.]com domain. All these records pointed to a single, high-privilege account interacting with crucial infrastructure: a Microsoft Entra ID SAML endpoint, a Mimecast email security gateway, a document-signing platform, and a U.S. federal government portal. The recurrence of this account across records from February to August 2026 suggests either unrotated credentials or repeated reinfection of the same workstation. The exposure window for these credentials spans from February 7 to August 10, 2026. The exposure of an identity provider credential holds significant implications for an organization, potentially enabling lateral movement and email interception. This profile strongly indicates a corporate intrusion risk. While the stealer-log evidence does not definitively confirm that Interlock utilized this specific credential to gain access, the persistent, high-privilege nature of the exposed identity against critical infrastructure aligns with typical ransomware kill chains. Infostealer-harvested credentials are a well-documented entry vector for threat actors like Interlock. Attackers or access brokers frequently acquire these logs to validate corporate credentials and subsequently gain access to systems such as Microsoft 365, VPNs, or remote-access portals, which then leads to ransomware deployment. It is crucial to reset the compromised account, revoke its active sessions, and audit sign-in and email forwarding activities across the entire exposure window. The endpoint associated with this credential should be treated as a candidate for thorough forensic review.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.