Product
Microsoft Defender
- First Reported
- Aug 26, 2026
- Latest Reported
- Sep 29, 2026
Reported Context (4)
- When a scheduled task runs, it adds an exclusion to Microsoft Defender to evade detection and communicates with the C2 server to receive additional commands. JSCEAL Malware Spread Through Fake Cryptocurrency Exchange Ads on Facebook
- [T1562.001 ] Impair Defenses: Disable or Modify Tools – It weakens Microsoft Defender by excluding its files and process names from scanning [‘Adds Windows Defender exclusions using PowerShell’] Kothamine RAT Uses Tailscale’s Tailcat for Encrypted Command-and-Control
- that uses fake loading screens, browser full-screen tricks, and runtime decryption to display bogus Microsoft Defender or Apple alerts and push victims to call a scam support number. Google Ads Deliver Fake Tech-Support Lockers Impersonating Microsoft Defender and Apple
- After creating another persistence mechanism, it configures Microsoft Defender exclusions by adding registry entries and adding exclusions for VSSVC.exe, ctfmon.exe, C:\Drivers, and C:\Windows\System32 directory. Cambodia-Focused Malware Campaign Uses Multi-Stage Infection Chain and SparkRAT
CVE (1)
Malware (4)
Threat Actors (1)
MITRE ATT&CK (30)
Vendors (8)
Products (14)
Tools (1)
Countries (5)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.