logo

Interlock Ransomware Exploits Zero-Day in Gaming Anti-Cheat Driver to Disable EDR, AV

ID: 20b2f89a-7061-5b53-a93c-a5c401438a39

STIX ID: report--20b2f89a-7061-5b53-a93c-a5c401438a39

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Interlock ransomware operators used a newly observed BYOVD DLL (“polers.dll” / Hotta Killer) that drops a signed, vulnerable anti‑cheat kernel driver (UpdateCheckerX64.sys, vulnerable to CVE‑2025‑61155) to terminate endpoint security processes during a targeted intrusion; the attack chain included MintLoader initial access, malicious Node.js implants (NodeSnakeRAT/Interlock RAT), ScreenConnect and RDP for hands‑on activity, and observable IoCs and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.