Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationeducation-sector-threatendpoint-security-bypassdata-exfiltration-method

Interlock Ransomware Uses BYOVD Anti-Cheat Driver Flaw to Disable EDR

Updated 3mo agoFirst seen Feb 4, 20263 sources

Fortinet/FortiGuard Labs reported that the Interlock ransomware group—described as a smaller, non-RaaS operation—ran a months-long intrusion campaign primarily targeting the education sector in the US and UK. Initial access was observed via MintLoader, including “ClickFix” social-engineering lures, followed by post-compromise activity using a JavaScript implant referred to as NodeSnakeRAT, lateral movement with valid accounts and living-off-the-land techniques, and broad discovery prior to impact. The operation follows a double-extortion pattern, with data exfiltration (including use of AZcopy) preceding ransomware deployment, and has been observed impacting both Windows endpoints and Nutanix hypervisor environments.

A key technical finding is Interlock’s use of a Bring Your Own Vulnerable Driver (BYOVD) technique to neutralize endpoint defenses. Researchers identified a custom tool dubbed “Hotta Killer” (associated with polers.dll) that drops a kernel driver UpdateCheckerX64.sys, described as a renamed vulnerable anti-cheat driver (GameDriverx64.sys, CVE-2025-61155). Because the driver is legitimate and digitally signed, it can pass initial trust checks; once loaded, it is abused for kernel-level process termination to kill EDR/AV processes, with reporting noting targeting of Fortinet security tooling specifically, enabling subsequent ransomware execution with reduced detection and response capability.

Share:
Interlock Ransomware Uses BYOVD Anti-Cheat Driver Flaw to Disable EDR
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Feb 4, 20265mo ago

Fortinet discloses Hotta Killer BYOVD technique tied to Interlock

Fortinet publicly reported that Interlock used a custom EDR/AV killer called Hotta Killer, which exploited a zero-day in the signed anti-cheat driver GameDriverx64.sys via a BYOVD technique. The flaw was tracked as CVE-2025-61155 and was used to terminate security software, including Fortinet products, at kernel level.

Oct 10, 20259mo ago

Attackers create thousands of rogue domain accounts after encryption

Following the start of encryption, the attackers generated roughly 5,000 rogue domain user accounts. The purpose was unclear, but FortiGuard suggested it may have been intended to create confusion or hinder incident response.

Interlock launches ransomware on Nutanix and Windows systems

On October 10, 2025, Interlock began encryption using a Linux encryptor against Nutanix servers and a JavaScript payload called jar.jar against Windows endpoints. The operation affected both hypervisor and endpoint environments.

Sep 1, 202510mo ago

Interlock escalates to large-scale data exfiltration with AZcopy

By September 2025, the attackers had escalated the intrusion by exfiltrating more than 250 GB of data using AZcopy to cloud storage. This activity supported the group's double-extortion model before encryption was launched.

Mar 31, 20251y ago

Attackers establish persistence with NodeSnake RAT

After initial access, Interlock deployed a custom JavaScript implant known as NodeSnake RAT to maintain long-term access and support lateral movement using valid accounts and living-off-the-land techniques.

Interlock begins intrusion via MintLoader in education-sector victim

FortiGuard Labs reported that an Interlock ransomware intrusion against the education sector began with a MintLoader infection, likely delivered through ClickFix social engineering. The campaign targeted education organizations in the U.S. and U.K.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Threat actors
1 linked
Affected products
3 linked
WindowsPowershellRemote Desktop Protocol (Rdp)
Organizations
4 linked
FortinetCyber Security NewsNutanixMicrosoft Corporation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Interlock Ransomware Uses BYOVD Anti-Cheat Driver Flaw to Disable EDR | Mallory