Ransomware Group Disables Windows Defender Remotely

Ransomware Group Disables Windows Defender Remotely

First seen 23 Nov 2025, 03:36 UTC WtopKtarAzcentral 20.3

Article Content

Browse articles
ThreatCluster

A ransomware group has developed a method to remotely disable Microsoft’s Windows Defender using a trusted Windows driver. This exploit allows criminals to turn off the security tool without triggering any alerts, raising concerns about the reliability of the software. Users are advised not to rely solely on Windows Defender for protection.