Rise of Fake Windows Defender Alerts and Ransomware Exploits

Rise of Fake Windows Defender Alerts and Ransomware Exploits

First seen 2 Dec 2025, 18:33 UTC WtopKtarAzcentral 10.2

Article Content

Browse articles
ThreatCluster

A recent report indicates that ransomware groups have developed methods to remotely disable Windows Defender, a built-in security tool from Microsoft, using trusted Windows drivers. This vulnerability allows criminals to turn off security alerts without detection, leading to an increase in fraudulent alerts aimed at gaining remote access to users' computers. Users are advised to be cautious and not rely solely on Windows Defender for protection.