Last seven days
- First activity
- Aug 3, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2
- Host form
- 0 IP / 45 hostnames
Defendnot is a tool abused to disable Microsoft Defender on Windows by registering a fake antivirus product with Windows Security Center (WSC), including via the IWscAvStatus interface, causing Defender to automatically turn itself off to avoid conflicts.
Profile source: Mallory opens in a new tabDefendnot
Defendnot is a tool abused to disable Microsoft Defender on Windows by registering a fake antivirus product with Windows Security Center (WSC), including via the IWscAvStatus interface, causing Defender to automatically turn itself off to avoid conflicts. The content describes it as a research tool originally designed to demonstrate weaknesses in the Windows Security Center trust model, later repurposed operationally in malware campaigns.
Behavior described in the content includes process injection into a trusted Microsoft-signed process such as Taskmgr.exe, interaction with undocumented or vendor-oriented WSC APIs, and fraudulent antivirus registration. In some reporting, Defendnot components were deployed as defendnot.dll and defendnot-loader.exe under %PROGRAMDATA%, with injection telemetry potentially visible via Sysmon Event IDs 7, 8, and 10 and process creation via Event ID 4688. Optional persistence artifacts mentioned alongside its use include autorun registry entries and scheduled task creation or modification.
Defendnot appears in a multi-stage phishing campaign primarily targeting users and organizations in Russia. In that campaign, victims were lured via compressed archives containing business/accounting-themed decoys and malicious LNK files that launched PowerShell to retrieve additional stages from GitHub. After privilege escalation attempts through repeated UAC prompts, the malware disabled Defender through PowerShell configuration changes, exclusions, and Defendnot deployment, then proceeded with reconnaissance, screenshot capture, Amnesia RAT installation, and Hakuna Matata-derived ransomware/WinLocker deployment. Associated infrastructure and tooling mentioned in the content include GitHub and Dropbox for payload hosting and Telegram Bot API for operator notification and exfiltration.
High-confidence indicators and artifacts directly mentioned in the content include Defendnot registering a fake AV in Windows Security Center, possible visible registration of a fake antivirus product in the GUI, Defender state changes, deployment paths such as %PROGRAMDATA%\defendnot.dll and %PROGRAMDATA%\defendnot-loader.exe, and abuse of Taskmgr.exe as an injection target. The primary purpose consistently described is defense evasion through neutralization of Microsoft Defender rather than direct exploitation of Defender itself.
C2 tracking
Derp observations, rolling seven-day window
Samples
187979252bdf6e932753613b86202ce215132ccca8236215321c5c67b1de7875 3e68725df6872b5201f2462426b7b1b41aa8b3d7c1525b5be89f7e9d4032aac6 47ccf7af5db91cfd6774898fe25950ec95ac5a9cc44334603259b2c10bca7b8a cfecc2bc043b4b5e3d412bea8664227cb437b0deb1e75657a933e38492a8a1c8 dbd1aae6e2a47af68e987dbfcc91c564d17c532e892938983eac8f891dec81b9 dd1bf6486965d831246279c59076aa1606cd3a81926cb6ff314c3f4ed3184455 3bc3448d0f2247595195bb8a6adf75d4c5a1b5a447b5bd837d10ba56005fbe00 3f9bc68b162fbef5450712960caddd5da632362731761b3a97b015cdf3ac9b51 7ab98bfe86df9a42e26cef109a9690781ea8a1e840488c8720797817053630b3 82b86020e04387bdcb72613bb097ec1673b03f0776e96eb49737a1f6a15b9ceb MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.