FortiGuard Labs details a full Interlock ransomware intrusion against a North American education organization spanning March–October 2025. The attack chain began with a MintLoader infection delivering NodeSnakeRAT via Node.js, followed by Interlock RAT deployment, ScreenConnect installation for persistent GUI access, and 250GB+ data exfiltration via AZcopy to Azure. A novel BYOVD tool called 'Hotta Killer' exploited a zero-day in a gaming anti-cheat driver (CVE-2025-61155) to attempt killing Fortinet EDR processes. Ransomware was deployed as both a JavaScript file targeting Windows endpoints and an ELF binary targeting Nutanix hypervisors, using hybrid RSA+AES encryption. The post includes deep technical analysis of Interlock RAT's C2 protocol, the Hotta Killer kernel driver mechanism, a custom browser infostealer, and the JavaScript ransomware's partial-encryption logic, along with IOCs and high-ROI defensive recommendations.

41m read timeFrom feeds.fortinet.com
Post cover image
Table of contents
Executive SummaryIntrusion TimelineIntrusion DetailsConclusionRecommendationsMITRE ATT&CK Mapping & ObservablesFortiGuard ProtectionsEngaging the FortiGuard Incident Response TeamIndicators of Compromise (IOCs)