Game Over: Interlock Ransomware Weaponizes Anti-Cheat Zero-Day to Kill EDR
ID: 33f5a5a7-9e89-5592-8aa7-f3fbb79ee0d5
STIX ID: report--33f5a5a7-9e89-5592-8aa7-f3fbb79ee0d5
Feed Name: securityonline.info
Threat Score
Interlock, a small but sophisticated ransomware group, ran a months-long campaign against the education sector that abused a zero-day in a signed gaming anti-cheat driver (CVE-2025-61155) to bypass defenses and kill EDR, established persistence with MintLoader and the NodeSnake RAT, exfiltrated ~250GB of data with AzCopy, and culminated in destructive encryption of Nutanix servers and Windows endpoints while creating ~5,000 rogue domain accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
