Interlock Ransomware Exploits Zero-Day in Gaming Anti-Cheat Driver to Disable EDR, AV
ID: 20b2f89a-7061-5b53-a93c-a5c401438a39
STIX ID: report--20b2f89a-7061-5b53-a93c-a5c401438a39
Feed Name: GBHackers
Threat Score
Interlock ransomware operators used a newly observed BYOVD DLL (“polers.dll” / Hotta Killer) that drops a signed, vulnerable anti‑cheat kernel driver (UpdateCheckerX64.sys, vulnerable to CVE‑2025‑61155) to terminate endpoint security processes during a targeted intrusion; the attack chain included MintLoader initial access, malicious Node.js implants (NodeSnakeRAT/Interlock RAT), ScreenConnect and RDP for hands‑on activity, and observable IoCs and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
