ThreatCluster

Interlock Ransomware Targets Education with Gaming Anti-Cheat Driver Exploit

First seen 4 Feb 2026, 22:55 UTC GbhackersCybersecuritynews 37

Article Content

Browse articles
ThreatCluster

The Interlock ransomware group has launched attacks primarily against the education sector in the U.S. and U.K., utilizing a new tool that exploits a zero-day vulnerability in a gaming anti-cheat driver. This exploit allows the ransomware to disable endpoint detection and response (EDR) and antivirus (AV) solutions, enhancing its effectiveness in infiltrating targeted systems.