logo

Game Over: Interlock Ransomware Weaponizes Anti-Cheat Zero-Day to Kill EDR

ID: 33f5a5a7-9e89-5592-8aa7-f3fbb79ee0d5

STIX ID: report--33f5a5a7-9e89-5592-8aa7-f3fbb79ee0d5

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-02-04

Date Updated: 2026-04-23

Author: Ddos

...
...

Interlock, a small but sophisticated ransomware group, ran a months-long campaign against the education sector that abused a zero-day in a signed gaming anti-cheat driver (CVE-2025-61155) to bypass defenses and kill EDR, established persistence with MintLoader and the NodeSnake RAT, exfiltrated ~250GB of data with AzCopy, and culminated in destructive encryption of Nutanix servers and Windows endpoints while creating ~5,000 rogue domain accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.