Skip to content
Ransomware Group Disables Windows Defender Remotely

Ransomware Group Disables Windows Defender Remotely

First seen 23 Nov 2025, 03:36 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A ransomware group has developed a method to remotely disable Microsoft’s Windows Defender using a trusted Windows driver. This exploit allows criminals to turn off the security tool without triggering any alerts, raising concerns about the reliability of the software. Users are advised not to rely solely on Windows Defender for protection.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (3)