Interlock Ransomware Actors New Tool Exploiting Gaming Anti-Cheat Driver 0-Day to Disable EDR and AV
The Interlock ransomware group has recently emerged as a significant threat, particularly targeting the education sector in the United States and United Kingdom.
The Interlock ransomware group has recently emerged as a significant threat, particularly targeting the education sector in the United States and United Kingdom.
Interlock operates as a small, dedicated team, independently developing and managing proprietary malware. This approach contrasts with the common Ransomware-as-a-Service (RaaS) model, showcasing a high level of sophistication and adaptability.
The group's attacks typically begin with a MintLoader infection, likely initiated through social engineering tactics. Following initial access, often facilitated by a JavaScript implant known as NodeSnakeRAT, attackers move laterally across networks using valid accounts and living-off-the-land binaries. This allows them to establish persistence and carry out extensive system discovery. The impact of these intrusions is severe, involving both data theft and encryption.
Data Exfiltration and Double-Extortion
Interlock utilizes tools like AZcopy to exfiltrate large volumes of data to cloud storage before deploying ransomware. This double-extortion tactic provides additional leverage over victims, even if backups are available.
Interlock operates as a small, dedicated team, independently developing and managing proprietary malware.
Analysts have identified the use of unique tools by Interlock to disable security defenses after establishing a foothold. This enables them to execute ransomware payloads on both Windows endpoints and Nutanix hypervisor environments without interference.
A critical component of Interlock's tactics is the "Hotta Killer" evasion tool, designed to neutralize Endpoint Detection and Response (EDR) and antivirus software. This tool uses a "Bring Your Own Vulnerable Driver" (BYOVD) technique, exploiting a zero-day vulnerability in a legitimate gaming anti-cheat driver, originally named GameDriverx64.sys (CVE-2025-61155). By using a renamed version, UpdateCheckerX64.sys , the malware executes privileged commands in the kernel space.
Once active, the "Hotta Killer" tool creates a symbolic link to communicate with the malicious driver, targeting processes associated with security software. By passing Process IDs of security tools to the driver, the malware forces the kernel to terminate them, effectively bypassing organizational defenses before encryption begins.
To mitigate these threats, organizations should:
Block execution of unauthorized remote access software. Restrict workstation-to-workstation SMB and RDP connections. Block outbound PowerShell network connections to prevent initial download of malicious payloads.
Based on reporting by Cyber Security News.
