Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Interlock Ransomware Actors New Tool Exploiting Gaming Anti-Cheat Driver 0-Day to Disable EDR and AV

The Interlock ransomware group has recently emerged as a significant threat, particularly targeting the education sector in the United States and United Kingdom.

The Interlock ransomware group has recently emerged as a significant threat, particularly targeting the education sector in the United States and United Kingdom.

Interlock operates as a small, dedicated team, independently developing and managing proprietary malware. This approach contrasts with the common Ransomware-as-a-Service (RaaS) model, showcasing a high level of sophistication and adaptability.

The group's attacks typically begin with a MintLoader infection, likely initiated through social engineering tactics. Following initial access, often facilitated by a JavaScript implant known as NodeSnakeRAT, attackers move laterally across networks using valid accounts and living-off-the-land binaries. This allows them to establish persistence and carry out extensive system discovery. The impact of these intrusions is severe, involving both data theft and encryption.

Data Exfiltration and Double-Extortion

Interlock utilizes tools like AZcopy to exfiltrate large volumes of data to cloud storage before deploying ransomware. This double-extortion tactic provides additional leverage over victims, even if backups are available.

Interlock operates as a small, dedicated team, independently developing and managing proprietary malware.
نضال النعيم · Thehackingpost

Analysts have identified the use of unique tools by Interlock to disable security defenses after establishing a foothold. This enables them to execute ransomware payloads on both Windows endpoints and Nutanix hypervisor environments without interference.

A critical component of Interlock's tactics is the "Hotta Killer" evasion tool, designed to neutralize Endpoint Detection and Response (EDR) and antivirus software. This tool uses a "Bring Your Own Vulnerable Driver" (BYOVD) technique, exploiting a zero-day vulnerability in a legitimate gaming anti-cheat driver, originally named GameDriverx64.sys (CVE-2025-61155). By using a renamed version, UpdateCheckerX64.sys , the malware executes privileged commands in the kernel space.

Once active, the "Hotta Killer" tool creates a symbolic link to communicate with the malicious driver, targeting processes associated with security software. By passing Process IDs of security tools to the driver, the malware forces the kernel to terminate them, effectively bypassing organizational defenses before encryption begins.

Advertisement

To mitigate these threats, organizations should:

Block execution of unauthorized remote access software. Restrict workstation-to-workstation SMB and RDP connections. Block outbound PowerShell network connections to prevent initial download of malicious payloads.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories