CVE-2025-61155Active Exploitation

HIGHCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A user-mode process can open a handle to the driver device and send specially crafted IOCTL requests. These requests are executed in kernel-mode context without proper authentication or access validation, allowing the attacker to terminate arbitrary processes, including critical system and security services, without requiring administrative privileges.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 4 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-01-30); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-01-30: 1Mentions · 2026-02-05: 1Mentions · 2026-02-09: 1Mentions · 2026-06-03: 1Mentions · 2026-06-16: 1Exploit Tool / Code · 2026-01-30: 1Exploit Tool / Code · 2026-02-05: 1Exploit Tool / Code · 2026-06-03: 1Active Exploitation · 2026-01-30: 1Active Exploitation · 2026-02-05: 1Active Exploitation · 2026-06-03: 1Active Exploitation · 2026-06-16: 1Patch / Workaround · 2026-06-03: 1Technical Details · 2026-02-05: 1Technical Details · 2026-06-03: 101-3002-0502-0906-0306-16
Signal classification2 categories
Active Exploitation
480.0%
General
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-01-301
Active Exploitation1
2026-02-051
Active Exploitation1
2026-02-091
General1
2026-06-031
Active Exploitation1
2026-06-161
Active Exploitation1
Full discourse5 posts
  • 📕「マルウエアの教科書」著者 | 吉川孝志 | 増補改訂版🌟発売中@MalwareBibleJP
    Active Exploitation

    ランサムウェア攻撃グループ「Interlock」が、ゲーム用アンチチートドライバのゼロデイ脆弱性(CVE-2025-61155)を悪用してEDR/AVを無効化する新たな独自の回避ツール「Hotta Killer」を使用してきています。 こうした脆弱性のある正規のカーネルドライバを持ち込んで悪用する手口を「BYOVD(Bring Your Own Vulnerable Driver)」と呼びますが、BYOVDはランサムウェア攻撃でEDR回避の定番手法となっており、今回はゲームのドライバが悪用された形です。 以下のように、「ClickFix」や「LOLBin」に「BYOVD」と、あらゆる効果的な典型手口を組み合わせてきていますね。 【経緯のまとめ】 ・Interlockは初期侵入にソーシャルエンジニアリングの手口である「ClickFix」を用い、MintLoader経由でJavaScriptインプラント「NodeSnakeRAT」を展開。 ・侵入後は正規アカウントと「LOLBin」(Living-off-the-Land Binaries)を駆使してラテラルムーブメントを実施。 ・データ窃取にはAZcopyでクラウドストレージへ大量のファイルを持ち出し、その後ランサムウェアを展開。 ・EDR/AV無効化に使われる「Hotta Killer」は正規のアンチチートドライバ「GameDriverx64.sys」のゼロデイ(CVE-2025-61155)を悪用し、リネームした「UpdateCheckerX64.sys」としてドロップ。 ・ツール本体はDLL(polers.dll)としてシステムプロセスにインジェクトされ、悪意あるドライバとシンボリックリンク経由で通信。 ・「Forti*.exe」などのパターンでセキュリティ製品のプロセスを検出し、対象のPIDをドライバに渡してカーネルレベルで強制終了。 ・WindowsエンドポイントだけでなくNutanixハイパーバイザー環境も攻撃対象。 【推奨される対策】 ・未承認リモートアクセスツールの実行をブロック ・ワークステーション間のSMB/RDP接続を制限 ・PowerShellのアウトバウンドネットワーク接続をブロックし、初期ペイロードの取得を阻止 https://cybersecuritynews.com/interlock-ransomware-actors-new-tool-exploiting-gaming-anti-cheat-driver-0-day/

    Post summary

    Interlock has been actively exploiting the zero‑day CVE‑2025‑61155 in the GameDriverx64.sys driver with their custom tool "Hotta Killer" to disable EDR/AV during ransomware operations.

    010142143.3K
    5.0K followersView on X
  • blueblue@piedpiper1616
    General

    GitHub - pollotherunner/CVE-2025-61155: Official public advisory for CVE-2025-61155 - https://github.com/pollotherunner/CVE-2025-61155

    Post summary

    The reference points to a GitHub repository labeled as an official public advisory for CVE-2025-61155, but no additional information or details about the vulnerability, PoC, or mitigation are provided.

    0802482.9K
    5.5K followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Active Exploitation

    🚨 GÜVENLİK BÜLTENİ: DragonForce Fidye Yazılımı MS Teams Altyapısını Arka Kapı Olarak Kullanıyor (CVE-2023-52271 / CVE-2025-61155 / CVE-2025-1055) Merhaba #Brolyz Fidye yazılımı gruplarının savunma atlatma tekniklerinde kritik bir gelişme raporlandı. Symantec ve araştırmacılara göre DragonForce, Komuta ve Kontrol (C2) trafiğini gizlemek için Microsoft Teams’in TURN relay altyapısını kötüye kullanıyor. Bu yöntem özellikle #orta ve büyük ölçekli kurumların ağ güvenliğinde ciddi kör nokta oluşturuyor. 📌 Özet Saldırganlar ilk erişimi genellikle yamalanmamış MSSQL/SQL sunucuları üzerinden sağlıyor. İçeri girdikten sonra Go tabanlı özel bir arka kapı (Backdoor.Turn) yükleniyor. Bu yazılım, Microsoft kimlik servislerinden geçici Teams token’ı alarak meşru Microsoft altyapısı üzerinden QUIC tabanlı iletişim kuruyor. Böylece C2 trafiği normal MS Teams görüşmesi #gibi görünerek güvenlik katmanlarını atlatabiliyor. Ek olarak BYOVD tekniğiyle güvenlik ürünlerini devre dışı bırakma girişimleri de gözlemleniyor. ⚠️ Riskler • C2 trafiğinin MS Teams gibi meşru servislerin içine gizlenmesi • Güvenlik duvarı ve IPS sistemlerinin saldırıyı tespit edememesi • Uzun süre fark edilmeden ağ içinde kalıcılık ve yatay hareket • Veri sızdırma (Data Exfiltration) ve fidye şifreleme aşaması 🛠️ Çözüm ve Öneriler 1️⃣ Süreç Bazlı Kontrol: Yalnızca meşru teams.exe süreçlerinin Teams altyapısına erişmesine izin verin. 2️⃣ BYOVD Koruması: WDAC üzerinden Microsoft Vulnerable Driver Blocklist’i aktif edin. 3️⃣ SQL Güvenliği: İnternete açık MSSQL/SQL sunucularını kapatın ve yamalayın. 4️⃣ Threat Hunting: AD üzerinde şüpheli hesap oluşturma ve yetki yükseltme aktivitelerini analiz edin. 🔍 Unutmayın: Saldırganlar artık güvenilir bulut servislerini doğrudan gizlenme katmanı olarak kullanıyor. Sıfır Güven (Zero Trust) yaklaşımını tüm ağ mimarinize uygulamayı unutmayın. Güvenli haftalar dilerim! 🛡️

    Post summary

    The post confirms that DragonForce ransomware is actively exploiting CVEs by covertly using Microsoft Teams as a C2 channel, but it lacks detailed technical or patch information.

    01050110
    420 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Interlock ransomware group pivots from user-driven attacks to zero-day exploitation, deploying AI-generated Slopoly backdoor to bypass security controls. Active campaign exploited Cisco FMC vulnerability for 36 days before patching. Key technical details: • CVE-2026-20131: Zero-day in Cisco Secure FMC enabling root RCE via crafted HTTP requests with serialized Java • Slopoly backdoor: AI-generated PowerShell C2 framework with WebSocket persistence and real-time communication • Hotta Killer: Custom utility exploiting CVE-2025-61155 in GameDriverX64.sys for kernel-level EDR disabling (T1685) • Memory-resident Java webshells intercept HTTP requests, decrypt commands, execute in-memory to evade AV • LOLBAS abuse: BITSAdmin, PowerShell, AZCopy for staging, lateral movement, and Azure Blob exfiltration (T1567.002) Attack chain methodology: • Phase 1: Shifted from drive-by downloads to direct infrastructure targeting via network edge vulnerabilities • Phase 2-3: Volatility for credential extraction, Certipy for AD CS privilege escalation, NetSupport RAT deployment • Phase 4-5: Advanced Port Scanner reconnaissance, RDP pivoting to DCs/Exchange, HAProxy nodes for exfiltration masking • Phase 6: PsExec domain-wide ransomware deployment with .interlock extension and !__README__!.txt notes Hunt for AZCopy activity to unfamiliar Azure destinations, NetSupport/AnyDesk from servers, and recurring /api/commands HTTP beaconing patterns. #DFIR_Radar

    Post summary

    Interlock ransomware leverages a zero‑day in Cisco Secure FMC, actively exploiting it for over a month and deploying a custom backdoor, while also possessing a suite of exploitation and persistence tools.

    10031708
    1.8K followersView on X
  • Fenikso@fenikso_io
    Active Exploitation

    Tu driver de anti-cheat de videojuegos puede ser la puerta de entrada para un ransomware. El grupo Interlock usa BYOVD con Hotta Killer para anular EDRs (CVE-2025-61155). IOCs detallados en las imágenes. FaaS de Fenikso detecta lo que otros ignoran. https://t.co/j1WP274LtD

    Post summary

    El grupo Interlock está aprovechando activamente CVE‑2025‑61155 mediante BYOVD y Hotta Killer para evadir EDRs, sin que se mencione parche ni detalles técnicos del fallo.

    00020138
    420 followersView on X

Explore more