Skip to content

Defendnot

DefendNot is a Windows defense-evasion tool that abuses Windows Security Center antivirus-registration functionality to register a fraudulent antivirus product.

Profile source: Mallory opens in a new tab

Defendnot

Family profile

DefendNot is a Windows defense-evasion tool that abuses Windows Security Center antivirus-registration functionality to register a fraudulent antivirus product. This can cause Microsoft Defender to disable itself to avoid a perceived conflict with another security product. The tool has been associated with loading or injecting its payload into Task Manager and interacting with Windows Security Center antivirus-status interfaces. It can also be used alongside scheduled-task or autorun persistence mechanisms. DefendNot originated as a research tool demonstrating weaknesses in the Windows Security Center trust model, but has been repurposed in malware operations to neutralize Microsoft Defender before deployment of follow-on payloads. It has been observed in campaigns targeting Windows users and organizations in Russia, including operations delivering Amnesia RAT and Hakuna Matata-derived ransomware.

Capabilities

  • Defense Evasion
  • Persistence
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Oct 2, 2026
Last activity
Oct 3, 2026
Feed role
C2 / Distribution
Host form
1 IP / 3 hostnames

Leading locations

  • CH1
  • NL1
  • RU1
  • US1

Leading providers

  • ALEXHOST SRL1
  • Cloudflare, Inc.1
  • JSC IOT1
  • Omegatech LTD1

Infrastructure traits

  • Hosting 4
  • Anycast 1

Samples

Recent associated samples

MITRE ATT&CK

Defendnot in ATT&CK

14 distinct techniques

Reporting

Research mentioning Defendnot

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.