logo

Interlock Ransomware Actors New Tool Exploiting Gaming Anti-Cheat Driver 0-Day to Disable EDR and AV

ID: 2c70149e-2470-5022-938e-66d9d245be1f

STIX ID: report--2c70149e-2470-5022-938e-66d9d245be1f

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-02-04

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report profiles the Interlock ransomware group as a small, sophisticated operator targeting primarily education-sector organizations in the US and UK; they use MintLoader and a JavaScript implant (NodeSnakeRAT) for initial access, exfiltrate data with AZcopy for double-extortion, and deploy a custom EDR/AV bypass named "Hotta Killer" that uses a renamed vulnerable gaming driver (CVE-2025-61155) and a DLL (polers.dll) to terminate security processes before encrypting systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.